3 ms·
It's not hard to encrypt the messages if you use an existing, secure library to do the work. What's hard is making it impossible for someone other than the int
by SomeCallMeTim 11y ago
It's not hard to encrypt the messages if you use an existing, secure library to do the work.
What's hard is making it impossible for someone other than the intended recipient to decrypt the message. How do you get the key to the recipient? Using something like a secure chat? Oops, that's what you're trying to create.
Maybe DH key exchange? [1] It's not rocket science to implement, but mistakes are possible. Also, unless you're sure that you're talking directly to the person you think you are, a MITM could be performing the key exchange with each end, and again you have someone overhearing you. So in addition to a proper DH implementation you need some way for the people to verify that the tokens exchanged match.
tl;dr: Yes, it's really that hard.
[1] https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exchange https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc...