3 ms·
Basically, Diffie Hellman is a key exchange algorithm, without authentication. So using just this algorithm would not protect from MITM. But the OTR protocol c
by geal 13y ago
Basically, Diffie Hellman is a key exchange algorithm, without authentication. So using just this algorithm would not protect from MITM.
But the OTR protocol can be effectively adapted to email. It would need a few emails to establish the original key exchange, but that's not too hard to do. In fact, TextSecure, an Android app (soon on iOS) already does OTR like that for SMS.
The real problem with a system like this is deciding how you would authenticate the person with whom you're communicating. Pre shared key? PGP-signed message?