5 ms·
It's an "intentional vulnerability". It's there to prevent users from being annoyed. Which is a bit of a lame excuse, because users would only be "annoyed" in v
by whyoh 10y ago
It's an "intentional vulnerability". It's there to prevent users from being annoyed. Which is a bit of a lame excuse, because users would only be "annoyed" in very rare cases and special circumstances, namely: A sends a message to B while B is offline AND then B gets a new phone before coming back online.
Even if you disagree with me that it's a very rare case, WhatsApp could still give us an option to show a confirmation before automatically re-sending messages to a new device.
- FabHK 10y agoIt's not that rare. It happens anytime the other user gets a new phone, or re-installs WhatsApp. > WhatsApp could still give us an option to show a confirmation before automatically re-sending messages to a new device. Just to clarify: they do optionally notify you (off by default), but after having re-sent the re-keyed messages. It would be nice if they (optionally) offered you a choice to re-send the message, or discard it. (You could then verify key fingerprints out of band before making that choice.) Doing that (making it "blocking") would leak information, OpenWhisperSystems argues, correctly.
- whyoh 10y ago>It's not that rare. It happens anytime the other user gets a new phone, or re-installs WhatsApp. That, and the messages also have to be sent while the user is offline, otherwise there is no vulnerability--assuming you enabled the currently available notifications. So I still believe it's a very rare circumstance and very few people would get "annoyed" by a notification/confirmation for that specific circumstance. >It would be nice if they (optionally) offered you a choice to re-send the message, or discard it. That's exactly what I had in mind.
- FabHK 10y ago> and the messages also have to be sent while the user is offline, otherwise there is no vulnerability a) the notification and concomitant irritation to non-technical users is there when the other user switches phone, whether they were online or not b) the vulnerability is there when the server is compromised, whether the other user is online or not (can just filter out "delivery receipts")