5 ms·
If the client doesn't trust the server, the crypto protocol is a little irrelevant. I otherwise agree that we (ostensibly) are in a better place now with pre-d
by ustolemyname 6y ago
If the client doesn't trust the server, the crypto protocol is a little irrelevant.
I otherwise agree that we (ostensibly) are in a better place now with pre-defined curves.
- dcow 6y ago> If the client doesn't trust the server, the crypto protocol is a little irrelevant. What? No. The protocol is the only thing that is relevant. Peers don't generally trust each other a priori at all. They trust the protocol. If they can authenticate each other within the bounds of the protocol then they trust each other. If one party no has reason to distrust a certain protocol, then it should not be used as a basis for establishing trust. If the two peers can't agree on a protocol: stalemate. If I compromise your server and only serve weak protocols a responsible client won't authenticate me whereas a vulnerable client would take my word that my protocol is secure.
- kortilla 6y agoWe’re talking about rotation though, something that can be triggered when both sides are authed.
- deleted 6y ago[deleted]
- PeterisP 6y agoIf don't trust a server, then any strong protocol that results in a secure shared secret or session key is trivially sidestepped by the server intentionally leaking these secrets or keys.
- ben_w 6y agoTwo interpretations of the same phrase: 1. Do you trust that 123.123.123.123 is the real https://example.com https://example.com ? 2. Do you trust the real https://example.com https://example.com to not leak? The protocol is for 1. You’re right that nothing can help with 2.
- dependenttypes 6y agoI trust the server only after I verify its PK. SSH performs mutual authentication.