Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mradestock
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
mradestock
11y ago
Just to clarify, the attack you want to protect against is that of an adversary being able to conclude the DH public key exchange with a bona fide weave peer, despite having no knowledge of the password. Correct? But what can an adversary l
2.
▲
by
mradestock
11y ago
I don't think that feature ever existed. Though a representation in a particular character set does not prevent the password from being strong.
3.
▲
by
mradestock
11y ago
> All of the privacy and integrity you could produce with the system described is what comes from the password. That is correct. I guess calling this a 'password' is perhaps misleading in our docs, since it could be seen as imp
4.
▲
by
mradestock
11y ago
> "they do not use a password hashing function" From the weave crypto docs at http://weaveworks.github.io/weave/how-it-works.html#crypto : "The public key from the remote peer is combined with the priv