5 ms·
If the messenger encryption doesn't feature end-to-end PKI, or at the very least some form of session-based cipher that is not sharing any private keys with yah
by xarball 13y ago
If the messenger encryption doesn't feature end-to-end PKI, or at the very least some form of session-based cipher that is not sharing any private keys with yahoo's network, it's ultimately ineffective.
If I may, yahoo -- Less preaching to the choir, and more straight up 'yes/no(s)' about who can read their personal data. If the data is accessible to yahoo, it is no longer personal.
(It's very simple concept!)
- yeukhon 13y ago> If the messenger encryption doesn't feature end-to-end PKI, or at the very least some form of session-based cipher that is not sharing any private keys with yahoo's network, it's ultimately ineffective. Exactly how do you do that without changing how Yahoo makes money? continue to provide what they do currently (spam filter, smart label etc, ads recommendation)? Multiple devices? Key management? One way is simply encrypted with user's password but Yahoo knows your password. Simple concept but complicated setup. I am not aware of any efficient and effective methods yet to solve all the above. I'd happy to learn.
- sgy 13y agoAll traffic through Yahoo data centers will be encrypted by default. They will be implementing security measures like HSTS and Certificate Transparency + support for TLS 1.2, 2048-bit RSA keys and Perfect Forward Secrecy.
- yeukhon 13y agoFrom an article: Yahoo has also turned on HTTPS encryption on its home page, search queries that run on the home page and most of its properties. Yahoo supports TLS 1.2, Perfect Forward Secrecy and 2048-bit RSA encryption for its home page, mail and digital magazines, Stamos said. He added that users can initiate encrypted sessions for Yahoo News, Sports, Finance and Good Morning America on Yahoo by typing HTTPS in the URL. He also promised an encrypted version of Yahoo Messenger in the coming months. I don't think OP is looking for PFS. I think he's looking for perfect encryption end-to-end so only he can decrypt the content, which means Yahoo will only receive an encrypted payload which Yahoo! cannot decrypt.
- sgy 13y ago1. Although I don't believe that you can make something that you can't break down or recover in the future, but you never know; it has affected their business, and a serious fix is required. 2. PFS is only for public-key protection, not ciphers. 3. Quantum computers that solve discrete logarithm problems very fast, can and will nearly break anything (http://goo.gl/IukwL3 http://goo.gl/IukwL3) 4. Have a look at Telegram's MTProto https://core.telegram.org/mtproto https://core.telegram.org/mtproto