Talk:Sender Keys
Add topic| This article is rated Start-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | ||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||
Comments left by AfC reviewers
[edit]
Comment: Thanks! Niche is maybe not the right word - the question is really if the topic has received coverage beyond the original inventor(s). For example, if a certain phrase is mentioned in a few PLDI/POPL papers but nowhere else, I would take that as a sign it's a neologism invented for the sake of those papers (which isn't to say it must not be a hugely important concept, just that we don't know that until independent authors have covered it!) Anyway, I think this will not be the case for this topic, it sounds like it's notable beyond the original inventing organization(s), so we just need to show that. Re: research articles, it depends on the context. I.e., whether these are original research about the topic, or independent reporting on that topic (e.g. review/survey articles). Based on what you said, there may be an argument for the research papers being secondary. Hope this is helpful! Caleb Stanford (talk) 05:23, 12 August 2025 (UTC)P.S. Nice find on the textbook. I can try to dig up a copy. And computerphile: it should be usable. Some people consider anything on youtube to be a dubious source (WP:RSPYT), but if it's a verified account for a well-known publication or expert (in this case, Brady Haran), I'd consider that reliable. Whether it is primary or secondary again depends on the type of content. Caleb Stanford (talk) 05:34, 12 August 2025 (UTC)
Comment: Thanks for your help. Some additional comments for the future reviewer:- There is a nice youtube video describing Sender Keys from Computerphile with 255k views ("What's Up With Group Messaging? - Computerphile"). Is this sufficient to be considered a wikipedia-grade secondary source? (I am a first time contributor, I do not know)- I have discovered a textbook, "Signal and Messaging Layer Security," that claims to have a section on Sender Keys (see: https://us.artechhouse.com/Signal-and-Messaging-Layer-Security-P2439.aspx). However, I cannot currently verify its contents at the moment because annas archive seems to be down :(- Are research articles simply always classified as primary? In my view it is simply incorrect to classify any of the papers I've mentioned in my last comment as primary. None of them offer an "original" description of the Sender Keys protocol, and all of them analyze other sources (WhatsApp x2, and Matrix)- Are papers published in top academic security/crypto venues really considered niche? I guess for the PL equivalent, would you still consider a PLDI/POPL paper niche?
Comment: I would decline based on the below, but I will leave this for someone who is an expert in cryptography/security to review. I initially declined based on the three sources provided by the author, but the author has come up with new sources (in top security venues, but not well-cited and still all research papers) to attempt to support. Thanks! Caleb Stanford (talk) 00:56, 12 August 2025 (UTC)
Comment: Hi Jake: "Device-Oriented Group Messaging" is a passing mention. Signal is SPS so does not count for GNG anyway. That leaves "WhatsUpp with Sender Keys?" and "Formal Analysis of Multi-Device Group Messaging in WhatsApp": These are research articles so may be classified as primary. I'm not clear on if the authors are connected to the Sender Keys protocol. Are there really no public news articles, technical articles, or textbooks mentioning this protocol? The standards for inclusion on Wikipedia are really quite stringent, we need high-quality independent articles covering that this is important, not just a few niche research articles studying it. Caleb Stanford (talk) 00:54, 12 August 2025 (UTC)
Comment: Hi Caleb, thanks for your comments. I will enumerate my points below:- "WhatsUpp with Sender Keys? Analysis, Improvements and Security Proofs" is peer-reviewed and was published in AsiaCrypt 2023 (A-tier crypto venue)- "Formal Analysis of Multi-Device Group Messaging in WhatsApp" is peer-reviewed and was published in EuroCrypt 2025 (S-tier crypto venue). Here is an associated news article: https://cyberinsider.com/weaknesses-discovered-in-whatsapps-multi-device-group-messaging/- "Device-Oriented Group Messaging: A Formal Cryptographic Analysis of Matrix’ Core" is peer-reviewed and was published in IEEE S&P 2024 (S-tier security venue)- About the blog post from Signal, it pre-dates the usage of the terminology "Sender Keys," but describes the mechanism Sender Keys employs. - To briefly argue the case for this article not being "too soon," it is highly evident Sender Keys (or its equivalent construction by Matrix, called Megolm) is highly impactful and widely deployed (WhatsApp, FB messenger, Matrix, etc). However, besides academic literature analyzing the protocol and some sparse documentation from the assorted whitepapers, there is not very much discussion online. Hence, this article should exist.
Comment: Just another note I noticed: the Signal blog post doesn't appear to mention "Sender Keys". So in fact, that wouldn't count as coverage of the topic either. May be WP:TOOSOON? I'm not super familiar with the subject matter. Caleb Stanford (talk) 19:39, 11 August 2025 (UTC)
Comment: Thanks @JakeGinesin: I'm sympathetic to your efforts to make an article for this interesting protocol, but unfortunately, these sources cannot be used to satisfy WP:GNG. The Signal source and FB internal report are primary. The paper, "WhatsUpp with Sender Keys"? appears to be a preprint research paper, see WP:PREPRINTs, generally not reliable until it is peer-reviewed, and it is not yet widely cited. All three are self-published sources (WP:SPS).What we need: 3 sources that are secondary, independent of the subject, and provide reliable, in-depth coverage. Think: news articles covering the protocol, textbooks written by 3rd parties not involved with the original definition, or peer-reviewed papers in top cryptography conferences that have been well-cited by the community. Caleb Stanford (talk) 19:37, 11 August 2025 (UTC)
Comment: Three sources for review (as requested by Caleb Stanford)- Balbas et al. WhatsUpp with Sender Keys? Analysis, Improvements and Security Proofs. https://eprint.iacr.org/2023/1385. This provides a formal description of Sender Keys, as well as proofs of various security properties, under the random oracle model. - Moxie Marlinspike. Private Group Messaging. https://signal.org/blog/private-groups/. The canonical, dare I say, original(?) blog post describing the server-side fan out-based encryption scheme now known as Sender Keys. One can also reference the Sender Keys implementation still present in the modern Signal codebase. https://github.com/signalapp/libsignal/blob/main/rust/protocol/src/sender_keys.rs- Facebook. Messenger End-to-End Encryption Overview. https://engineering.fb.com/wp-content/uploads/2023/12/MessengerEnd-to-EndEncryptionOverview_12-6-2023.pdf. Facebook's specification for the end-to-end encryption of Messenger, including a description of Sender Keys. WhatsApp provides similar documentation (see the references).
Comment: Please post WP:Three sources as an AFC comment, like this, on the draft page. Caleb Stanford (talk) 12:31, 11 August 2025 (UTC)
Notability
[edit]Hi @Bunnypranav: Bringing the discussion here.
I'm not an expert on the topic, but I was the one who reviewed the AfC. It would appear that this is a core protocol that is used by Signal, WhatsApp, Messenger, and others and there are academic publications in major computer security and cryptography venues discussing the concept.
I was pretty sure that is sufficient for GNG - can you share your perspective? Thanks! Caleb Stanford (talk) 15:39, 3 September 2025 (UTC)
- Hey @Caleb Stanford, thanks for the ping. As of now, I do not have any comments on the possible notability for this topic, but I do have concerns regarding the current sourcing. Of the sources listed, two are from Meta/WhatsApp themselves, two are blogs, and the other three seem to be Wikipedia:SELFPUBLISHED. Only the latter 3 can even be considered reliable, that too I feel they are quetionable. Because of this, I feel that the notability, though it may exist, cannot be properly established and proven through the given sources. Hope this helps! ~/Bunnypranav:<ping> 10:27, 4 September 2025 (UTC)
- Hi @Bunnypranav: Thanks for the reply. My initial impression was actually similar (as you can see from the previous AfC comments on this page ha). AsiaCrypt 2023, EuroCrypt 2025 and S&P 2024 (passing mention) are not self-published. These are academic research papers published at major security and cryptography venues. I don't think they are primary with respect to Sender Keys though they are primary with respect to their own research contributions. I don't have my hands on a copy of the listed textbook, but it may also support GNG. That being said, it would certainly be nice to have some additional third-party news coverage. Caleb Stanford (talk) 16:35, 4 September 2025 (UTC)
- Thanks, this seems to be slightly better (sorry for not paying much attention to above comments). I still even one additional media coverage, maybe even that of those papers will go a long way (was one of them mentioned above?). After that, feel free to remove the tag on my behalf. ~/Bunnypranav:<ping> 03:45, 5 September 2025 (UTC)
- Thanks.
was one of them mentioned above?
Yes, the three papers are the three sources you mentioned. I was able to get access to the textbook. Currently I have the two papers + the textbook as supporting GNG, and some other news articles only as passing mentions. Seems to be the best I could find for now... Caleb Stanford (talk) 15:04, 5 September 2025 (UTC)- By one of them I meant media coverage. Atleast link them for now, and feel free to remove the banner, you have convinced me with the sources :p ~/Bunnypranav:<ping> 16:27, 5 September 2025 (UTC)
- For completeness here are more news sources:
- - A blog post from Trail of Bits, one of the most reputable cryptographic auditing firms, discussing encrypted group chats. https://blog.trailofbits.com/2019/08/06/better-encrypted-group-chat/
- - An announcement from Meta regarding multi-device capability. https://engineering.fb.com/2021/07/14/security/whatsapp-multi-device/
- The Messaging Layer Security RFC, RFC9420, also mentions Sender Keys as a key motivation for the construction of the protocol. JakeGinesin (talk) 17:34, 8 September 2025 (UTC)
- @JakeGinesin: Worth adding these to the article! These are both primary I'm pretty sure (so not helping with GNG), but still useful to add as sources. Caleb Stanford (talk) 17:53, 8 September 2025 (UTC)
- By one of them I meant media coverage. Atleast link them for now, and feel free to remove the banner, you have convinced me with the sources :p ~/Bunnypranav:<ping> 16:27, 5 September 2025 (UTC)
- Thanks.
- Thanks, this seems to be slightly better (sorry for not paying much attention to above comments). I still even one additional media coverage, maybe even that of those papers will go a long way (was one of them mentioned above?). After that, feel free to remove the tag on my behalf. ~/Bunnypranav:<ping> 03:45, 5 September 2025 (UTC)
- Hi @Bunnypranav: Thanks for the reply. My initial impression was actually similar (as you can see from the previous AfC comments on this page ha). AsiaCrypt 2023, EuroCrypt 2025 and S&P 2024 (passing mention) are not self-published. These are academic research papers published at major security and cryptography venues. I don't think they are primary with respect to Sender Keys though they are primary with respect to their own research contributions. I don't have my hands on a copy of the listed textbook, but it may also support GNG. That being said, it would certainly be nice to have some additional third-party news coverage. Caleb Stanford (talk) 16:35, 4 September 2025 (UTC)
- Start-Class AfC articles
- AfC submissions by date/17 August 2025
- Accepted AfC submissions
- Start-Class Cryptography articles
- Unknown-importance Cryptography articles
- Start-Class Computer science articles
- Unknown-importance Computer science articles
- WikiProject Computer science articles
- WikiProject Cryptography articles
- Start-Class Computer security articles
- Unknown-importance Computer security articles
- Start-Class Computer security articles of Unknown-importance
- Start-Class Computing articles
- Unknown-importance Computing articles
- All Computing articles
- All Computer security articles


