3 ms·
This doesn't prove anything, but: > Without authenticating, hand the encrypted envelope to the service along with the recipient’s delivery token. Source: http
by niel 4y ago
This doesn't prove anything, but:
> Without authenticating, hand the encrypted envelope to the service along with the recipient’s delivery token.
Source: https://signal.org/blog/sealed-sender/#:~:text=Without%20authenticating https://signal.org/blog/sealed-sender/#:~:text=Without%20aut...
The sender's client sends a certificate derived from the recipient's profile key.
This certificate is sent to the server as the header "Unidentified-Access-Key" - you can see how this header is derived from the Signal clients' source.
So yes, these API calls are authenticated, but not using the sender's credentials in any way.