[messaging] How secure is TextSecure?

Taylor R Campbell campbell+moderncrypto at mumble.net
Thu Nov 6 07:42:21 PST 2014


   Date: Thu, 6 Nov 2014 15:39:02 +0000
   From: Taylor R Campbell <campbell+moderncrypto at mumble.net>

      Date: Thu, 6 Nov 2014 07:02:37 -0800
      From: Trevor Perrin <trevp at trevp.net>

      We can add crypto, but in any system where Bob presents his contact
      and authentication info to Alice there's going to be this risk.
   [...]
   Before Alice texts `I love you!' to the number/key she just received,
   she texts `Is this Bob?'.
                      ^^^
Ahem, that should be `Charlie', to match Trevor's scenario, unless
Alice has preemptively guessed that her prankster roommate Bob is
playing yet another joke on her.


More information about the Messaging mailing list