|
|
|
|
|
by palata
33 days ago
|
|
> Now i don't know what signal does That makes me question how much you know about end-to-end encrypted messengers, because Signal is the gold standard. > I am almost certain WhatsApp can just lie about your contacts keys and man in the middle the connection. The problem there is that WhatsApp is not open source, so you can't check. So obviously you have to trust. But there are many, many employees who have access to the WhatsApp sources, so if it was not implementing what it says it is, chances are that someone would have said it. Also thanks to the EU DMA we have some protocol published by WhatsApp. |
|
No one in Microsoft, Yahoo, Google, Facebook, AOL, Skype, or Apple said anything about PRISM. We had to wait for the NSA whistleblower. So the argument someone would say something does not really stand up to historical precedent.
I looked a bit into it and yeah they have a key transparency mechanism where they store a blockchain on s3.
So supposedly they can't just add a key for a user in secret. But still what if they do it in public does the client refuse to send messages to new keys?
It's not like we are all spending all our time going over a random s3 bucket to say `Aha, I am sure Bob didn't add this new key because he logged in from his desktop. It has to be a man in the middle`
Can they just siphon keys of your device? Can they just deploy a special version to just your device without the vast majority of engineers in meta even knowing about the compromised version? No one knows. Well no one in public.
The gold standard would be personally managed keys, exchanged and signed by your contacts in person, open source software that is not auto-updating, distributed over a channel that does not know your identity.