logoalt Hacker News

baschyesterday at 4:56 PM1 replyview on HN

That might be a different pin? Messenger requires a pin to be able to access encrypted chat.

Every time you sign in to the web interface or resign into the app you enter it. I don’t remember an option for an alphanumeric pin or to offload it to a third party.


Replies

solenoid0937yesterday at 5:17 PM

Oh my bad! I was talking about WhatsApp.

The Messenger PIN is rate limited by an HSM, you merely enter it through the web interface.

Of course, the HSM could be backdoored or the client could exfil the secret but the latter would be easy to discover.

Harder to do any better here without making the user memorize a master password, which tends to fail miserably in real life.