Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So someone reporting a message to Facebook would be the equivalent of that person (either Alice or Bob) reporting and sending the content of the other person's encrypted conversation to a third party.

The Signal Protocol provides end-to-end encryption so you don't have to trust the intermediate parties/servers involved in relaying the message (e.g. you don't have to trust Facebook's servers), and to protect against the other person reporting and revealing your conversation to someone else, the Signal Protocol provides message repudiation [1], which effectively gives the sender plausible deniability because the receiving party cannot prove to a third party that a message came from you.

[1] https://en.wikipedia.org/wiki/Signal_Protocol#Properties



Yes, my concern is that this functionality is baked into the client and is at a high risk of being executable remotely.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: