4 ms·
Using the Diffie-Helman would be good practice, but it's not enough to assume a defence against a malevolent actor who controls the client. It's not about the
by acoard 5y ago
Using the Diffie-Helman would be good practice, but it's not enough to assume a defence against a malevolent actor who controls the client. It's not about the key exchange itself.
Essentially, a determined malevolent actor who controls the client could exfiltrate your keys easily. Maybe it's intentionally introducing a subtle vulnerability and then exploiting it server-side[0], or it's just simply doing a file upload of the keys. Basically, you can't be certain there isn't a backdoor from a malevolent actor.
[0] IIRC, there was some vulnerability in the Linux Kernel a few years ago that was basically there due to an errant space. Some people theorized that this could have actually been intentionally introduced by sophisticated actors, to hide in plain-sight open source code.