7 ms·
I wonder how they "confirm[ed] out of email that the keys we exchanged were not intercepted and replaced by your surveillants." Key exchange is the hardest part
by joelanders 12y ago
I wonder how they "confirm[ed] out of email that the keys we exchanged were not intercepted and replaced by your surveillants." Key exchange is the hardest part.
- pointernil 12y agoWho doesn't ;) Any speculations? Ideas? Agreeing on an entropy source is one thing, but really exchanging keys out of NSAs sight is hard, right?
- theintern 12y agoThat was my thought as well. Given all communication is considered compromised, I can't think of a simple way to do this that isn't a face to face.
- DINKDINK 12y agoCould you explain how exchanging PGP keys over TLS would be compromised or compromisable?
- belovedeagle 12y agoSimple. Analog man-in-the-middle; i.e., you're not talking to who you think you're talking to. That's the whole point of key exchange.