2 ms·
Correct, an app would need to read the audio stream and do some preparatory DSP to extract audio short codes. Of course you could build standards in at a point
by nonrandomstring 3y ago
Correct, an app would need to read the audio stream and do some
preparatory DSP to extract audio short codes.
Of course you could build standards in at a point closer to the radio
basebands. I mean, why is basic source authentication not built in as
far back as SS7 given we had the technology even in the 1970s?
The only time you'd be using the app would be if receiving a call from
an untrusted caller. And if you don't trust the app period, then the
game is off anyway. In theory the same app could hold certs from a
number of "trustworthy" sources you might like to check; much like a
TLS certificate.
But in the end you'd wind up with too many, and hard to keep track of,
and then buffoons like those from the EU commission would be wanting
to "force trust" upon you to authenticate "approved government
sources" - Which sadly is the problem with all source authentication
schemes that work with PKI this way. You really need to keep the
application layer relation 1-to-1.
I prefer simpler, elegant solutions - like your bank should never
call you or push ANYTHING which is why I called it both a good and
bad idea, and generally I distrust the whole ecosystem, of "apps"
anyway.