Recently the French Government required its members to use it, but it's made by a French startup, AFAIK.
With the demos we've seen feels absolutely doable, but for now requires quite some effort.
But even tampering seems pretty easy if the attacker has a more modest objective, of having you and your buddy each talking to one of the attacker's henchmen using voice changers. The emoji verification won't help here -- each henchman just gives the emoji for their respective conversation.
I feel it is implied that the latency is low enough (a few 100s of ms) to not impede the conversation, and that the parties have talked before and would notice if the tone of the conversation was completely different. Or maybe I'm misunderstanding.
To defend, could ask to verify emojis at a random point in the middle of the call to make the attacker's life more difficult. Especially right before discussing sensitive information ;-)
Or drip verify over the course of the call, e.g. "what's your 3rd emoji?", and listen for signs of an attacker cutting in and out.
https://www.npr.org/2023/03/22/1165448073/voice-clones-ai-sc...
https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-...
My thinking is, you might as well get in the habit of defending yourself now. The alternative is to monitor how widespread the attack is and only adjust your policy once it becomes "sufficiently" widespread. But I don't think that's even a labor savings, since defending yourself isn't actually that hard.
Do you have the projection of some binary string in the unicode emoji space? (then you'd need to chunk it and possibly use many emojis)
So is it the representation in emojis of a server controlled shared secret?
That'd make 2 clients talking to eachother through the server vulnerable to tampering at the server level (ex:MITM)
Shouldn't the 2 clients not involve the server for the secret? This would require each of them being able to access the other public key fingerprint without trusting what the server says. But if they see eachother fingerprint projected into the unicode emoji space, they would see different emojis.
I think I may be missing something obvious. I just don't understand this trick.
Emojis take up 32 bits each. So 4 emojis would be 128 bits.
Of course, this doesn't account for all the 4 byte unicode combos that don't result in an emoji, but still.
> The emphasis on the eyes in this style is reflected in the common usage of emoticons that use only the eyes, e.g. ^^
I always interpreted "^^" as equivalent to "this" or "ditto" -- arrows pointing at the immediately prior message. In hindsight, it could just as easily have been happy eyes!
That's... a good thing to be aware of as a heavy ^^ user myself! Thanks for sharing
sincerely,
the man in the middle
ps confirming this out of band will not add to your security