3 ms·
I love the comment! Thank you some_furry. You're a quick code reader. You're correct that it doesn't offer key rotation or forward secrecy. That's something I
by apayan 6y ago
I love the comment! Thank you some_furry. You're a quick code reader.
You're correct that it doesn't offer key rotation or forward secrecy. That's something I definitely want to add (assuming anybody actually finds this service useful).
> One thing I didn't see was message padding of location data prior to encryption, to prevent side-channel attacks via ciphertext length. [7] I don't know if I missed this, or if it was omitted.
You didn't miss it. It's not there. It's something I should add.
- some_furry 6y agoIf you're interested in using the X3DH handshake that Signal specified, I ported a slight variant of it (which uses libsodium) in TypeScript not too long ago: https://github.com/soatok/rawr-x3dh https://github.com/soatok/rawr-x3dh There's no low-level crypto code here, just high-level protocol stitching. This is still something you'd want to hire experts to review if you built it in Java, of course.