3 ms·
>or Signal have no means of verifying keys To be fair, you've always been able to verify safety numbers (i.e. fingerprints i.e. public key hashes). https://si
by bertman 6y ago
>or Signal have no means of verifying keys
To be fair, you've always been able to verify safety numbers (i.e. fingerprints i.e. public key hashes).
https://signal.org/blog/safety-number-updates/ https://signal.org/blog/safety-number-updates/
- aborsy 6y agoVerifying a public key over a secure channel works trivially for any public key cryptography system. I was referring to ways to establish such secure secondary channels. Either verify a key yourself, eg, in person, or use distributed trust to average out the noise. For example, keybase has an approach: linking various identity information to keys. Signal is secure in a strange narrow interpretation of the security. There are problems if you look more broadly.