3 ms·
It's exhausting to make this comment every time... but here we go. Key revocation is table stakes for secure messaging. I need a trusted way to relay that my c
by jryio 6mo ago
It's exhausting to make this comment every time... but here we go.
Key revocation is table stakes for secure messaging. I need a trusted way to relay that my contact's key has been revoked and I should stop trusting it.
Neither P2P, TLS, client-server, or any choice of key curve gives you this. Read the whitepaper, no mention of revocation. Correct me if I missed something.
- lxgr 6mo agoI feel like key revocation is usually solved via key replacement in most secure instant messengers. Every implementation that I know (which does not include SimpleX) offers some way to recover from complete key loss, at which point other parties receive a "the key for this contact has changed" notification, and that new key is then untrusted by default until verified out-of-band. (This does trust the server operators to not censor your re-registration, but that seems no different from most other centralized revocation mechanisms.) Do you have a scenario in mind where this would not be sufficient?
- ranger_danger 6mo agoCan't this be accomplished with a CRL for client-side certificates?