Hacker News new | past | comments | ask | show | jobs | submit login

That's not what I said. Signal stores the key that you've already verified. So changing the key in the keyserver doesn't do anything to a device, since you haven't verified the new key from the keyserver (and it shows a warning).



You think. Remember that you don't know what binary you were delivered, unless you personally reverse engineered it yourself.


Or compiled and side-loaded it yourself.


TOFU / POP

Trust on first use / persistence of pseudonym


Yes, that is the phrase I was looking for. :P




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: