3 ms·
It seems that the system relies on a single private key for secrecy, but deploys it widely - to every participating ISP. It seems difficult to believe that you
by trotsky 15y ago
It seems that the system relies on a single private key for secrecy, but deploys it widely - to every participating ISP. It seems difficult to believe that you could distribute a key like that and have it stay private, especially with so much active state sponsored cyber espionage going on.
I suppose you could solve this by generating a good number of key pairs and only deploying new secret keys to ISPs when there was evidence of disclosure, but if the government in question eavesdropped instead of blocked I'm not sure you'd find out quickly enough. It's unclear what advantages you'd get by eavesdropping, presumably little if it's really just used as a tunnel to tor.