3 ms·
Wonder if this affects Signal, too.
by JacobHenner 7y ago
Wonder if this affects Signal, too.
- joecool1029 7y agoMy gut tells me no. Signal switched over to using the Signal Protocol for call signaling. It had used a few different signaling standards over the years (when it used to be called Redphone). However, it's impossible to really know for sure as the server component for calls is a proprietary black box.
- jtl999 7y ago> However, it's impossible to really know for sure as the server component for calls is a proprietary black box. I thought that changed after migrating to WebRTC? Although I haven't tried to spin up my own Signal server, modify the APK and see what works and doesn't work.
- cottsak 7y agoAgreed. It seems more plausible that the "injected code" would be limited to (1) the WhatsApp app, and (2) the infrastructure outside of the Signal Protocol implementation. If true, this still poses a problem to comms/calls secured end-to-end with the Signal Protocol impl - because once decrypted on the client, the rest of the WhatsApp may be compromised and able to exfil comms. I will be surprised, if this vuln allows the attacker control outside of the WhatsApp app sandbox to other parts of iOS. (I will be less surprised if the above is possible in Android)