View Single Post
Posts: 2 | Thanked: 2 times | Joined on Dec 2013 @ Gothenburg
#23
Originally Posted by reinob View Post
It is doable, but only if (as in necessary, not sufficient) the key/password is typed by the user and never pre-stored on the phone.
I don't think we assume the phone to be compromised here, so storing a very long key on the phone in advance and then using it piece by piece is not problematic, if we're only concerned about end-to-end security (i.e. that no malicious base station or similar can read the messages).

If we assume that the attacker also controls the phone anyway, then he can just see the message directly.

To be clear, the idea is still extremely impractical, but password entry should not be the problem.
 

The Following User Says Thank You to dschoepe For This Useful Post: