Hi Andy, Thanks for responding!
On 30 March 2017 at 15:10, Andreas Straub <[email protected]> wrote: > You raise a valid point. I agree that this construction seems cleaner from > a purely theoretical standpoint. > Actually, it's the practical standpoint that worries me most, in that this is not practically implementable for non-GPL clients at the moment. Permissible implementations of XEdDSA may or may not emerge, but as long as it is not something available, you're taking a risk of making a standard that will never be adopted. (not even talking about things such as FIPS-certifiable, which I know even less about). Having to regenerate identity keys is a valid usability concern. I'm throwing the idea out there as an alternative, which has to be weighed against the alternative, given the availability of crypto algorithms for the approach to keep them, and bearing in mind the fact that we'll probably have to break compatibility with signal and previous OMEMO versions anyway. I agree that losing the audit is a downside, but I'm not sure if the alternative is realistic if you want your XEP to take off. Given the right choice of crypto primitives, implementing a library to do double ratchet itself doesn't sound that big of an undertaking (I did a prototype of the Olm version in C++ in an afternoon or 2, including getting my head around all this stuff). The bulk of the work lies in proper UIs for all this. thanks! Remko
_______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
