On Fri, 2017-10-06 at 15:42 +0200, Jeff Burdges wrote: > If ACKs do not advance the ratchet, then one could offer a "current > safety number" derived similarly to ratchet header encryption keys, > right?
Oops, ACKs that do not advance the ratchet do not make this work. There are more complex schemes that work under assumptions like synchronized clocks, but probably not worth the effort. Jeff
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Messaging mailing list Messaging@moderncrypto.org https://moderncrypto.org/mailman/listinfo/messaging