4 ms·
Yes, the public key is just attached to the outgoing messages and automatically imported by p≡p-capable software. That's kind of a TOFU (Trust On First Use) ap
by vx17h 10y ago
Yes, the public key is just attached to the outgoing messages and automatically imported by p≡p-capable software.
That's kind of a TOFU (Trust On First Use) approach, but you can verify trust by comparing the fingerprints, in p≡p by default represented as dictionary words in your natural language (somewhat similar to Signal). That's suitable for comparison by phone (=> quickly done).
- XorNot 10y agoIs there an indication of trust status? I.e. "auto imported" vs. Manually verified, and more importantly what happens when fingerprints change?
- vx17h 10y agoYes, there's a Privacy Status in p≡p, there being four different states: no color (mostly today: insufficient crypto, weak crypto, unknown), yellow/orange for accepted, transparent and well implemented crypto, green for crypto avoiding the MITM (Man-In-The-Middle) possibility (after the involved peers checked their Trustwords and accepted them to be trustworthy) and red if the p≡p engine detects an attack. Cf. the documentation for screenshots how this looks (nowadays): https://prettyeasyprivacy.com/docs https://prettyeasyprivacy.com/docs
- vx17h 10y agoMessages from or to a contact can also show red, I forgot to mention, if the user decides that the key pair used by that contact is not trustworthy. That can make sense if you see from the contents of a message (and subsequently perhaps by a phone call, adding evidence to that) that someone's in between or the key pair in place is not really belonging to the contact, but made up.