3 ms·
So the attack is due to the fingerprint of the key being smaller than the actual key and therefore theoretically possible to find another key with the same fing
by utnick 12y ago
So the attack is due to the fingerprint of the key being smaller than the actual key and therefore theoretically possible to find another key with the same fingerprint..
Doesn't textsecure and threema have the exact same problem? Both show a fingerprint to the user instead of the actual key.
- semi-extrinsic 12y agoIf that's the attack, then it's well known that PGP is also vulnerable to the same thing: http://www.asheesh.org/note/debian/short-key-ids-are-bad-news.html http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...