@Tony

On Sun, Jul 28, 2013 at 1:32 PM, Francisco Ruiz <ruiz at iit.edu
<https://mailman.stanford.edu/mailman/listinfo/liberationtech>> wrote:

>* - How do I communicate a password to Bob? Before I "get a crucial bit*>* of 
>information" to Bob, I need to first get a crucial bit of information*>* to 
>Bob?*>**>* Alice should send her Lock (public key) to Bob rather than 
>anything*>* secret.*>**
How? At the very least Alice/Bob need an authenticated/trusted channel for
this.

If Alice sends Bob her "public key" over an untrusted channel, it can be
intercepted by an MitM posing as Bob who can then intercept all traffic
between Alice/Bob

-- 
Tony Arcieri


Hi Tony, I actually worried about this quite a bit. The best solution I
could think of is making a hashed ID
 of the public key (PassLok has a button for that), which Alice/Bob can
dictate over the phone, thus authenticating
the key.

Any other ideas?

Francisco
--
Too many emails? Unsubscribe, change to digest, or change password by emailing 
moderator at [email protected] or changing your settings at 
https://mailman.stanford.edu/mailman/listinfo/liberationtech

Reply via email to