Cloudflare and Trail of Bits now audit who Signal says you are talking to
Here is the problem, and it is easier to state than most people expect. End-to-end encryption scrambles a message so only the recipient can read it.
That works perfectly, provided you were handed the recipient’s real key. The app fetches that key from a server.
If the server hands you a different key, the encryption still functions exactly as designed. It just encrypts your message to somebody else.
The attack that survives perfect encryption
Signal describes the threat plainly. A key gets swapped out without the owner knowing, for example if somebody compromised Signal itself.
Nothing looks wrong at either end. The padlock stays shut, the maths stays sound, and a third party reads everything.
Every encrypted messenger has carried this hole since the beginning. It is why Signal has always shown safety numbers, the long string you were meant to compare with your contact in person or over a...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE