Bob Mottram (bob)'s status on Friday, 13-Jan-2017 14:08:51 PST
-
So the explanation from OWS about #WhatsApp sounds maybe reasonable, but without source code the claimed behavior can't be verified. It also sounds as if the key change notification is turned off by default and that it's the server which detects the key change and notifies the clients (again we just have to take someone's word for that this is what happens).
So I think the Guardian criticism still holds:
"The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings"
That is, by default key changes are silent and the receiver is unaware if they happen. Bob could believe that he's talking to Alice, but could actually be talking to Alice through Eve.