4 ms·
Shouldn't they inspire the end to end encryption from openSSH. As far as I know it's used by many worldwide and it seems fairly secure. Maybe I am missing somet
by john37386 6y ago
Shouldn't they inspire the end to end encryption from openSSH. As far as I know it's used by many worldwide and it seems fairly secure. Maybe I am missing something though.
- ffk 6y agoIt looks like what they have now is openssh like. Client 1 sends data to the server encrypted. Server decrypts. Server reencrypts and sends to client 2. This describes how to communicate in such a way where the client 1 and 2 can communicate with the server in the data path and The server being unable to see the contents of the message. The hard part is key management between clients in a secure way.
- edoceo 6y agoYou said "server decrypts" but then also "server being unable to see contents". How? If I decrypt, I see contents.
- ffk 6y agoI was unclear in my comment. I was describing a before and after set of solutions. The former allows for server side decryption. The latter approach would prevent server side decryption.
- edoceo 6y agoNow I get it, thx
- SparkyMcUnicorn 6y agoI think he's wrong. The server never receives the key. The bridge passes along the encrypted stream and encryption/decryption only happens client side. In the demos, you can see that the parameter is a # parameter and not a query parameter.
- chupasaurus 6y ago1. OpenSSH is point-to-point, there's no one-to-many messages. 2. OpenSSH doesn't stop sessions for a user whose authorization info had changed, which is what Jitsy tries to change to prevent.