Hacker News new | past | comments | ask | show | jobs | submit login

They claim to use SIP to establish an SRTP connection with AES-256. But I don't know any way to verify that the data is being encrypted well or sent only to the intended recipient. https://ssl.apple.com/iphone/business/docs/iOS_Security_Feb1...



> But I don't know any way to verify that the data is being encrypted well or sent only to the intended recipient.

Couldn't you say the same thing about Signal? Both parties claim to use end-to-end encryption.


If you don't have a SAS phrase or some other way to aurally verify the other party, you can never be secure against a MITM. Signal does this, while I doubt it's available in FaceTime audio.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: