gerowen,
@gerowen@mastodon.social avatar

I find myself these days hesitant to even consider any private messengers if they don't have the option to verify which devices/keys have access to your messages. #Signal, #XMPP / OMEMO, #Matrix, hell even Facebook Messenger's E2EE chats let you verify which devices can read your messages. If you're encrypting your users' messages, but they can't verify whether a rogue device has access to their messages, then why even bother encrypting them?

#Encryption #Security #Cybersecurity #Privacy

jabberati,
@jabberati@social.anoxinon.de avatar

@gerowen If your contact has verified your OMEMO keys and a rogue key is added, messages are not encrypted to this key.

I wonder how other apps let you "verify" which other devices were added. In an ongoing MitM attack the server simply wouldn't tell you about the rogue keys. Maybe it's just security theater?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Signal
  • DreamBathrooms
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • InstantRegret
  • tacticalgear
  • provamag3
  • ethstaker
  • cisconetworking
  • modclub
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • normalnudes
  • megavids
  • Leos
  • anitta
  • JUstTest
  • lostlight
  • All magazines