3 ms·
Congrats on the launch! Your implementation of sharing from the whitepaper scares me. The second that the private key travels anywhere it's no longer safe in
by throwaway02394 5y ago
Congrats on the launch!
Your implementation of sharing from the whitepaper scares me.
The second that the private key travels anywhere it's no longer safe in my opinion.
This is why Signal uses the double ratchet and 1password has their own sharing. Unless I missed something.
- arpitagarwal 5y agoGreat point! We integrated the QR-code and link based sharing into the app to provide a seamless experience for users. However, we also have an email sharing solution already integrated into the app which uses public-key cryptography. This is protected from accidental leaks as you correctly pointed out. Thanks for the feedback, we would update our WhitePaper with the details from above, and also indicate that to users in the UI - so that it scares people less! ;)
- Comevius 5y agoThe whitepaper has no details about an authenticated key exchange like Signal does with X3DH, it just assumes that it already happened, but then the rest of their protocol does not offer any post-compromise security.