3 ms·
I'm not a crypto guy, but I'm trying to understand how this backdoor could be used by governments or WhatsApp/Facebook itself. I'm not entirely sure how such a
by kriive 10y ago
I'm not a crypto guy, but I'm trying to understand how this backdoor could be used by governments or WhatsApp/Facebook itself.
I'm not entirely sure how such an attack based on this backdoor would work.
The article says that WhatsApp servers have the ability to trigger the clients to generate new keys, but even with new keys how can the server read the messages at all? Has the server got a copy of the new generated keys?
Probably there is something big I'm missing.
- TwoBit 10y agoI'm trying to understand this same thing. I don't see why triggering a client to generate new keys is a problem. Giving the client keys to use is a problem, but that's not what it's saying. Edit: it is described much better here: https://tobi.rocks/2016/04/whats-app-retransmission-vulnerability/ https://tobi.rocks/2016/04/whats-app-retransmission-vulnerab... The idea is that in addition to the keys being regenerated, the recipient phone is spoofed (a key point not mentioned). So the FBI could tell the Whatsapp company to generate a fake recipient phone and connect the sender phone to that phone instead.
- kriive 10y agoThank you, now I understand.