Hacker News new | past | comments | ask | show | jobs | submit login

it’s not quite that brazen, but from what i remember the whatsapp server can push a new public key for your contact/chat to the device, which means that they can MITM you. the chat shows that the key changed, but most users wouldn’t know what that means and ignore it



Isn't that how Signal works too? What else would it do, disallow you from continuing the chat if the key changes?


Until reverification? Sure.


In that case most users similarly won't know what reverification means and will just click through without verifying anything. It's not reasonable to say that that makes Whatsapp only as secure as Twitter DMs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: