Conversation
Notices
-
rugk -> ⚠️ Follow me at https://social.wiuwiu.de/@rugk (rugk@gnusocial.de)'s status on Friday, 28-Jul-2017 13:54:57 UTC rugk -> ⚠️ Follow me at https://social.wiuwiu.de/@rugk More is Less: How group chats weaken the security of instant messengers #Signal, #WhatsApp and !threema https://eprint.iacr.org/2017/713.pdf
TL;DR: Attackers can often rewind members of group to previous state (replay attack), WhatsApp can add arbitrary users and thus circumvent #e2e crypto in all group chats easily.
BTW: #Threema fixed the issues, WhatsApp ignored, Signal wants to introduce a new protocol in the future.
/cc !verschluesselung