4 ms·
I worded that poorly and have edited the OP to reflect that. I was referring to the recently re-discovered paper about group chats (e.g. https://www.helpnetsec
by mahemm 9y ago
I worded that poorly and have edited the OP to reflect that.
I was referring to the recently re-discovered paper about group chats (e.g. https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-group-chats/ https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-g... paper here: https://eprint.iacr.org/2017/713.pdf https://eprint.iacr.org/2017/713.pdf)
- Forbo 9y ago> “The good news is that in Signal the attack is very difficult to execute,” Green noted. “The reason is that in order to add someone to your group, I need to know the group ID. Since the group ID is a random 128-bit number (and is never revealed to non-group-members or even the server) that pretty much blocks the attack. The main exception to this is former group members, who already know the group ID — and can now add themselves back to the group with impunity.” Sounds like making a mountain out of a molehill.
- mahemm 9y agoIt absolutely is! Which is why I felt like it was important to bring more attention to the much lesser security stance of others in the space.