4 ms·
Question for anyone who knows. What is the method by which the old signing keys are published? I've done a few google searches and haven't found any pages of us
by elrac1 5y ago
Question for anyone who knows. What is the method by which the old signing keys are published? I've done a few google searches and haven't found any pages of used signing keys for Signal. I know that the fact that if someone can decrypt the message then they could have created and signed the message leads to the deniability, but they were very specific about publishing the signing keys.
- watusername 5y agoSignal (since TextSecure v2) doesn't have to publish any signing key, because it uses a variant of OTR where messages are even more forgeable - you can forge complete transcripts with another person even when you haven't messaged them at all. https://signal.org/blog/simplifying-otr-deniability/ https://signal.org/blog/simplifying-otr-deniability/
- upofadown 5y agoI think that in the Signal case, anyone can generate forged messages in some sense. OTR pretty much only allowed your correspondent to do that. I personally don't think it matters as I consider deniability though a false claim of a forgery pretty much bogus to start with. I would actually prefer that messages from me could not be forged by anyone. I don't feel the need to have off the record discussions and chances are will never have that need.