7 ms·
Any reference to the trivial mitm attacks which signal has suffered?
by fylo 10mo ago
Any reference to the trivial mitm attacks which signal has suffered?
- upofadown 10mo agoThis is mostly about the usability issues that make such attacks work so well on Signal: https://www.ndss-symposium.org/wp-content/uploads/2018/03/09-when-signal-hits-the-fan-on-the-usability-and-security-of-state-of-the-art-secure-mobile-messaging.pdf https://www.ndss-symposium.org/wp-content/uploads/2018/03/09... This adds some detail about how Signal can do MITM attacks: https://sequoia-pgp.org/blog/2021/06/28/202106-hey-signal-great-encryption-needs-great-authentication/ https://sequoia-pgp.org/blog/2021/06/28/202106-hey-signal-gr... Some of the details might of changed since publication. My current understanding is that Signal doesn't even bring up the idea of identity verification if a user has not previously done it. So if anything, things have gotten worse.