4 ms·
It might be solvable with an external identity server that keeps the ID + key of users, but then you just move the problem of trust to another party. Additiona
by LockAndLol 6y ago
It might be solvable with an external identity server that keeps the ID + key of users, but then you just move the problem of trust to another party.
Additionally, that ID+key would have to be updated somehow by the user and now you have a new problem: how do you verify that the user is who they say they are? Telling them to digitally sign something is possible, but what if the private key is gone?
The Signal protocol solves what it can solve for now. If cryptography experts have suggestions to improve it, I'm sure they can contribute.
Is there any protocol that solves the issue you're describing? And that has a good app? And that isn't centralized? We're asking for the "eierlegende Wollmilchsau" aka unicorn.