On Fri, 2017-10-06 at 15:42 +0200, Jeff Burdges wrote:
> If ACKs do not advance the ratchet, then one could offer a "current
> safety number" derived similarly to ratchet header encryption keys,
> right? 

Oops, ACKs that do not advance the ratchet do not make this work.  There
are more complex schemes that work under assumptions like synchronized
clocks, but probably not worth the effort. 

Jeff


Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
Messaging mailing list
Messaging@moderncrypto.org
https://moderncrypto.org/mailman/listinfo/messaging

Reply via email to