3 ms·
Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal. In order for an active adversary to perform a s
by jlund 12y ago
Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal.
In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successfully determine when someone is seeing a fingerprint for the first time (or get lucky) and then successfully maintain their MITM position across every single network the device uses, forever. If they fail at either of those, the user will be warned.
I keep bringing up SSH because it's an example of a fingerprint verification system based on TOFU that works incredibly well at preventing MITM attacks. No one is having key signing parties with their servers, and yet connections remain secure.
- StavrosK 12y agoI agree, but it's much easier for me to tell a friend "hey is this your key?" when we're together than go all the way up to my server and connect directly to it. That's why I think that there should be a UI element that says "you're pretty secure, but if you just check this you're golden".