3 ms·
While we are at suggesting encrypted IM, I'm wondering something: I'm not using Whatsapp or Signal, but I have the feeling that for UX reason the users never ha
by goffi 7y ago
While we are at suggesting encrypted IM, I'm wondering something: I'm not using Whatsapp or Signal, but I have the feeling that for UX reason the users never have to validate a fingerprint (or QR code or anything similar). How is this working? They are using TOFU right (there will be a notice if the fingerprint change)? What happens if a user gets a new device? Can anybody with experience with those apps explains how it works?
Because e2ee doesn't really makes sense without proper authentication (we're talking about protecting against malicious server, right? So what happens if a server add a fake device or change fingerprint).
Conversations use Blind Trust Before Verification, that means that until a first fingerprint is checked, everything is accepted, so e2ee only protect against server archive/passive attacks, but not again an actually malicious server.
note: I'm a XMPP dev and I'm wondering how it's done in other apps as a point of comparison.
- upofadown 7y agoSignal basically trusts on first connection where you trust the Signal company to do something with an SMS to link your identity with your phone number. After that you have a fingerprint (they call it a "safety number") if you want to check to see if you are still talking to the same entity. It will warn you if the number changes. So how different that is from Conversations depends on how much you trust the Signal company and the phone company. In either case you really have to check the fingerprint, just like with everything. The issue is inherent to secure communications and can not be avoided with any sort of improved user interface.
- goffi 7y agoI see, so you can verify but it's not by default. What happens if you add a new device (e.g. a tablet so a new fingerprint, which is different from changing main device where the original fingerprint changes)? Is the new fingerprint accepted without user validation? My point is that e2ee makes sense when you don't trust the server (here Signal company, or FB for whatsapp), so if most people don't check the fingerprints (and I assume it's the case), what's the real value of it?
- lvh 7y agoThis is a core difference between Signal and eg WhatsApp. The Signal UX clearly shows who’s verified, and the UX clearly earns you when the safety number changes. Additionally, the secondary device model (eg Signal Desktop) goes to great lengths not to break that. With WhatsApp, you’re trusting WhatsApp.