4 ms·
I'm not a security expert, so could one of the security experts who frequent HN weigh in on this? Otherwise this looks super cool.
by pm 8y ago
I'm not a security expert, so could one of the security experts who frequent HN weigh in on this? Otherwise this looks super cool.
- thesimon 8y agoI'm not a security expert and can only point out one thing that I noticed from my knowledge from network security class in college: >Upon successful verification of the signature contained in the third message (and verification that the eight-byte timestamp is current), the server proceeds to send three symmetrical messages: a long term server public key, an ephemeral server public key, and a signature message authenticating the ephemeral key. This might be vulnerable to replay attacks. The user proves freshness of his request by sending a signed unix timestamp, the server however doesn't seem to do that. Shouldn't compromise the security of the protocol, just one thing that I noticed.
- lvh 8y agoI haven't audited the code, but did take a peek at the protocol. Nothing obviously busted from the description, but there are definitely some weird design choices. https://news.ycombinator.com/item?id=17393780 https://news.ycombinator.com/item?id=17393780