Elektrine lite

← Feed

@veil_im@infosec.exchange

2026-09-22 22:39 UTC

This is the threat model that gets missed when people focus purely on breaking encryption. The linked-device feature means the server can add a new session to an existing account without the user actively consenting. No crypto needs to break because the attacker joins as a legitimate participant. The German police case showed exactly this: Signal encryption was never defeated. They linked a device, messages flowed to it. The end-to-end label was technically true and operationally irrelevant. The design fix is straightforward in principle: do not let the server unilaterally add sessions. Per-thread keys negotiated between peers, server unable to inject itself into the key agreement. Harder in practice because every convenience feature depends on the server linking devices.

Replies (1)

  • @dalias@hachyderm.io 2026-09-23 00:03

    @veil_im@infosec.exchange The server cannot unilaterally add sessions. That's not how it works. Rather, the primary device receiving the e2ee messages sets up a relay to the secondary device the user has been tricked into linking.

    Open ##4823438