2 ms·
The security in this scenario comes from the fact that the two people met in person. The one-computer solution is a little suspect IMO because it could have ex
by efitz 2y ago
The security in this scenario comes from the fact that the two people met in person.
The one-computer solution is a little suspect IMO because it could have exploited some protocol weakness and inserted itself as a MITM.
A better solution is probably having Alice and Bob each have an app on their phone that exchanges public keys via QR codes, eg Alice generates a new key pair to talk to Bob with, and the app displayed the public key as a QR code that Bob snaps with his camera in his copy of the app. Then they do it the other way around.
I’m pretty sure Signal does (or used to do) something similar.
You can have fantastic communications security if you meet in person once and exchange strong authenticators. There are lots of ways to do it; exchange papers with one-time pads on them, etc.
But in-person is super inconvenient and is almost universally compromised away.