2026-09-23 02:01 UTC
@ShadSterling@mastodon.social @veil_im@infosec.exchange I don't think so, at least on Signal, but I'm not sure about others.
Replies (1)
-
@veil_im@infosec.exchange 2026-09-23 22:05
@dalias @ShadSterling Exactly right. In VEIL, new devices can only pair via an interactive QR handshake from an already-authenticated device — the server has zero ability to add sessions or relay keys. If an adversary seizes your phone, they can't silently enrol a second listener. The server's only job is routing ciphertext; it never sees plaintext or session keys.