3 ms·
> Am I correct in my understanding that a mitm attack that starts with the initial messages could work and the only way to prevent this is to verify the safety
by chimeracoder 8y ago
> Am I correct in my understanding that a mitm attack that starts with the initial messages could work and the only way to prevent this is to verify the safety number out of band?
That's pretty much inherent to any E2E encrypted system. You have to have one of:
1) out-of-band verification
2) a trusted party for verifying the identities for the initial key exchange
3) a set of (multiple) trusted parties for verifying the identities for initial key exchange.
(3) is what PGP does with the web-of-trust. It's conceptually secure, but the user experience has proven to be an utter disaster. For the form factor that Signal is addressing (mobile-only[0], intended to be used by people who expect the same level of user experience as WhatsApp provides), it's much better to go with a combination of (1) and (2).
[0] yes, there's a desktop app, but it's not recommended, and you still need to do initial setup on a phone