6 ms·
> Nonce's are "Numbers used ONCE", they 1) don't need to be secret and 2) ARE NOT encryption keys. We know. Putting the nonces in the handshake along with the
by irungentoo 13y ago
> Nonce's are "Numbers used ONCE", they 1) don't need to be secret and 2) ARE NOT encryption keys.
We know.
Putting the nonces in the handshake along with the session public key was simple.
In the NaCl docs it is advised that if you can keep the nonces secret that you do so.
- anologwintermut 13y agoOut of curiosity, why not use OTR for messaging?
- znq 13y agoProbably because OTR only works when both parties are online at the same time. Edit: that said I haven't looked at their solution. Maybe it has the same issues. Or worse.
- anologwintermut 13y agoLooking at their crypto code, it appears they assume both parties are online. There is a two way hand shake for key negotiation. My guess was they wanted to handle things like video chat and file transfer that OTR doesn't handle. But at least for video chat, I don't think it NACL will work out of the box either