3 ms·
There's one thing that I don't understand about checking keys in person. Since it's closed source, how do we know that WhatsApp is actually doing what they say
by Heliosmaster 5y ago
There's one thing that I don't understand about checking keys in person. Since it's closed source, how do we know that WhatsApp is actually doing what they say they do?
You have to trust them that "if the keys are the same in-person, then you're safe". But it's completely up to their implementation which we have no clue of.
- perryizgr8 5y agoYou're right. Although if you use any modern smartphone at all this is true for every single software you are running. Apple's store or Play store might be MITM'ing every single app on your phone and you would never know.
- Strom 5y agoSure, you have to have some trust. Even if you had access to the source, you wouldn’t know that the OS on the phone does what it claims. Then even if you audit and compile the OS from scratch, you also need to audit and compile from scratch the compiler. This is a long process, because you need to bootstrap the compiler compiling somehow. After all that work, you still can’t be sure. Because you also need to build your own semiconductors. You don’t really know that your CPU is doing what it claims, or that there isn’t a secret radio chip embedded into your RAM. You need to trust a lot of people to have any sanity. Adding WhatsApp on top of a pile of hundreds of companies isn’t that extreme.
- Heliosmaster 5y agoYes, i agree with you. Which is why I personally never bother checking the codes in person because I just trust WhatsApp
- saurik 5y agoBecause at the end of the day it is based on phone numbers you have to check those keys even if all of the software is secure, because people only rent phone numbers and they are even awkwardly easy to steal by sweet talking the carrier into letting you do a number port.