4 ms·
DCGKA has O(n) complexity, so more like Signal groups than MLS. Here's a version of MLS (By Alwen, Mularczyk, Tselekounis) which supports out order delivery of
by 0ptix 4y ago
DCGKA has O(n) complexity, so more like Signal groups than MLS.
Here's a version of MLS (By Alwen, Mularczyk, Tselekounis) which supports out order delivery of commits.
https://eprint.iacr.org/2023/394 https://eprint.iacr.org/2023/394
- ianopolous 4y agoThat's true, but not really relevant until you hit 1000s of chat members. MLS targets up to 50,000. But there isn't a plausible threat model for a secure chat that large (someone will leak or it will be infiltrated).
- kitkat_new 4y agoit's already relevant at 1000 members, and why not use it when it is possible? Also, switch messenger once you hit 1k? Even it a leak may be possible, it still isn't guaranteed. Instead you guarantee server side access without e2ee
- ianopolous 4y agoAt 1000 members a DCGKA key update (when the group membership changes) is ~300kb. So, equivalent to someone sending a small image, which they probably do very frequently.
- kitkat_new 4y agoper device? what about the computational costs involved (which may require wasm/js)?
- ianopolous 4y agoDon't get me wrong, FR-CGKA looks cool. I hadn't seen it yet, and am still reading it. Not sure why wasm/js is relevant to the discussion.
- kitkat_new 4y agowell, encryption needs computational resources; you have to expect higher overhead when you do encryption in the web compared to native code e.g. in Rust or C. It kind of is the upper bound of slowness ;)
- ianopolous 4y agoI thought the selling point of wasm was close to native speed. :-) If something is important browsers can always add it to webcrypto anyway.