5 ms·
It doesn't need to be encrypted, just signed by the entropy source. The signature should be verifiable without entropy.
by simulate-me 5y ago
It doesn't need to be encrypted, just signed by the entropy source. The signature should be verifiable without entropy.
- Hello71 5y agoHow does that prevent replay attacks?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- simulate-me 5y agoHmm good point. I guess you need entropy for a nonce.
- paulclinger 5y agoMaybe include and sign a timestamp?
- pronoiac 5y agoSorta nice, but that wouldn't avoid replay issues.
- deleted 5y ago[deleted]