4 ms·
It looks like what they have now is openssh like. Client 1 sends data to the server encrypted. Server decrypts. Server reencrypts and sends to client 2. This d
by ffk 6y ago
It looks like what they have now is openssh like. Client 1 sends data to the server encrypted. Server decrypts. Server reencrypts and sends to client 2.
This describes how to communicate in such a way where the client 1 and 2 can communicate with the server in the data path and The server being unable to see the contents of the message.
The hard part is key management between clients in a secure way.
- edoceo 6y agoYou said "server decrypts" but then also "server being unable to see contents". How? If I decrypt, I see contents.
- ffk 6y agoI was unclear in my comment. I was describing a before and after set of solutions. The former allows for server side decryption. The latter approach would prevent server side decryption.
- edoceo 6y agoNow I get it, thx
- SparkyMcUnicorn 6y agoI think he's wrong. The server never receives the key. The bridge passes along the encrypted stream and encryption/decryption only happens client side. In the demos, you can see that the parameter is a # parameter and not a query parameter.