4 ms·
Public keys are open, they can be distributed any way (they could be published to a hosted directory a shared wherever). Only the device that owns the private k
by ricksharp 9y ago
Public keys are open, they can be distributed any way (they could be published to a hosted directory a shared wherever). Only the device that owns the private key could decrypt the message.
In fact encrypted messages could be stored publically anywhere and only the intended recipient could read them.
The flow of messages is not encrypted, the system only encrypts message contents. (However, there are options to make it very difficult to trace, but that is a different issue.)
Trust is up to the user to decide and is always necessary.
Multiple devices is easy enough, a device can encrypt its own private key and send it to another device (using the target devices public key). The target device would now have 2 private keys for decryption.
- JetSpiegel 9y agoPublic keys are open, but the hard part is mapping real people to their public keys. How do you know that the public key they send is the real one, and wasn't modified en route? For people you know IRL, this is easy, but for strangers?
- snakeanus 9y agoYou could use OpenPGP public keys so you can use the web of trust that comes with them.