Oddbean new post about | logout
 No, MLS is suitable for large-scale group chats but not for one-on-one chats and small group chats. 

If MLS is used for one-on-one chats, in order to achieve forward secrecy and backward secrecy, MLS requires a special message to update the group key, and then the normal message can be sent. 

However, in the Signal protocol, the content needed to update the encryption key is attached to the normal message.