Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fputz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
fputz
6y ago
No, because 3DH requires pre-exchanged public keys. For Signal, this key exchange might happen automatically, but you still need to manually compare the fingerprints to achieve authentication.
2.
▲
by
fputz
6y ago
A regular Diffie-Hellman key exchange is not authenticated, meaning that you don't know who you establish a key with. To authenticate this key exchange, you would need some prior security context (e.g., some shared secret or TLS certif
3.
▲
by
fputz
6y ago
Acoustic communication is quite nice for this kind of ad-hoc provisioning, because it doesn't require any special hardware or prior pairing. One security issue is that if you do this in public, an attacker could initiate malicious conn