absolutely no proof it is e2e encrypted without the source.
WhatsApp's Signal Protocol integration is now complete
201–210 of 386 posts
Re: WhatsApp's Signal Protocol integration is now complete
#202Is it still the case that verifying a user's text identity does not verify their voice identity and vice versa? IMO it would be very nice if calling someone and verifying the short code would confirm their text identity as well and if, once someone's text identity is verified, if voice calls to that person were protected by the verified text identity. (IIRC the reason that Signal does not work this way is that texts…
WhatsApp uses a shared identity across text and voice, so Signal Protocol is used to secure both connections. We've long planned to do the same thing in Signal, but WhatsApp is ahead of Signal here. Axolotl is now called Signal Protocol, btw.
Re: WhatsApp's Signal Protocol integration is now complete
#203Is it open source? I can't find the source code anywhere.
Re: WhatsApp's Signal Protocol integration is now complete
#204absolutely no proof it is e2e encrypted without the source.
A smart comment would be a detailed analysis of the pros and cons of OpenSource in terms of verification. Your are barly more then a troll.
Re: WhatsApp's Signal Protocol integration is now complete
#205Earlier quoted context omitted.
> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/
It is killing me that you didn't rename Signal to Axolotl.
Axolotl is cool in a techy/underground sort of way (if your into that) but completely misses the boat on being 1) Easy to spell, 2) easy to pronounce, 3) easy to understand.
Mainstream users would just say "wtf" and move on to whatsapp/telegram/facebook messenger.
Re: WhatsApp's Signal Protocol integration is now complete
#206This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…
Re: WhatsApp's Signal Protocol integration is now complete
#207This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…
> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/
Re: WhatsApp's Signal Protocol integration is now complete
#208Earlier quoted context omitted.
> From that perspective, I'm still inclined to trust apple's iMessage a bit more especially after recent events. // edit: got my answer here: https://news.ycombinator.com/item?id=11432629 I'm curious, is that because of what they did in the FBI case, or for technical reasons? IIRC iMessage would allow Apple to add public keys which they (or the FBI/$ADVERSARY) control as a sort-of backdoor as well. I can't say that I…
The unfortunate reality too is that average users will never go to the extra trouble of authenticating keys themselves. I'm also more likely to trust a company like Apple or Google with key management than a "trusted third party" (simply because they're bigger companies, with more valuable brands to protect, and resources to throw at the problem). So, it feels like for the average consumer, a product like iMessage ti…
Re: WhatsApp's Signal Protocol integration is now complete
#209Earlier quoted context omitted.
Cool. So FB/WhatsApp can't even decrypt messages themselves?
If they actually do what they say the do, then yes. Thier is no evidence that they are lying, so for now its probebly save to assume that they can not read your messages.