Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption

<- View Parent
RIotingPacifist@lemmy.world ⁨9⁩ ⁨hours⁩ ago

creating a backdoor to access plaintext messages is still very difficult if the app is well audited

Well audited is key, this attack likely works by doing something like adding Meta to the list of trusted devices, then hiding itself from the list (either because of code in the client or because it the meta device is only added for a moment), so the backdoor wouldn’t be send_all_messages_to_hq(), it would be in the code to list trusted devices, either explicitly hiding some devices or some sort of refresh timer that’s known so you can avoid being there when the UI is updated).

Or it works through the some other mechanism that still preserves E2E encryption.

source
Sort:hotnewtop