HN user

lieuwex

197 karma

[ my public key: https://keybase.io/lieuwer; my proof: https://keybase.io/lieuwer/sigs/sjXgaco_SLXp8o084z0kuWwTQzJt_CC5YzT9W0yNRFs ]

Posts4
Comments22
View on HN
VimGraph 9 months ago

This function is user contributed. It's not official.

What kind of risk profile does one have when it is likely that both the password is known and malware has been installed on the phone, but also just access to an ephemeral login session by the attacker (which could be obtained even when using a secure enclave by waiting for the user to authenticate by themselves) would not be enough?

This is the exact same as DigiD, except that there is no cost per-auth, only per-sms. The parent comment is saying that Amsterdam wanted the users to install the DigiD app instead of relying on SMS authentication.

If you really mean conversations of the original owner, I can't believe that's true after e2e has been enabled.

But it could be that messages sent to the original owner are received, since WhatsApp automatically re-encrypts and sends messages if the message has not been received yet and the key has been changed. So basically that would mean the message would be sent when the previous owner already changed their number. So the people shouldn't have sent the messages at all.

WhatsApp e2e encryption just makes sure that the only person that can read the message is the owner of the number, not necessarily the person you want to send it to.

I think "kak" still would be translated better as "shit", you wouldn't curse with "POO!". But in Dutch you can curse with "KAK!", just as 'SH*T!' in English.