3 ms·
I'm trying to understand this same thing. I don't see why triggering a client to generate new keys is a problem. Giving the client keys to use is a problem, but
by TwoBit 10y ago
I'm trying to understand this same thing. I don't see why triggering a client to generate new keys is a problem. Giving the client keys to use is a problem, but that's not what it's saying.
Edit: it is described much better here: https://tobi.rocks/2016/04/whats-app-retransmission-vulnerability/ https://tobi.rocks/2016/04/whats-app-retransmission-vulnerab...
The idea is that in addition to the keys being regenerated, the recipient phone is spoofed (a key point not mentioned). So the FBI could tell the Whatsapp company to generate a fake recipient phone and connect the sender phone to that phone instead.
- kriive 10y agoThank you, now I understand.