3 ms·
I think building an iMessage-style PKI might be a wasted effort for them. They would need to immediately and silently inject server "participants" that listen i
by herf 7y ago
I think building an iMessage-style PKI might be a wasted effort for them. They would need to immediately and silently inject server "participants" that listen in to every conversation (for dial-in or recording), so the permission model is not much better than a shared ephemeral key. To some extent, the difference depends on logging--if you log the ephemeral key or throw it away (or similarly, if you throw away the made-up participant private key or keep it).
Maybe they should allow small groups to establish on-the-fly OTR-style conversations when they can.