Am 31.03.2017 um 11:04 schrieb Remko Tronçon:
> 1. We go back to Olm's protocol of establishing an initial shared
> secret, using regular 3DH instead of X3DH. 
>
>     + Moves us back to an audited, implementable algorithm
>     + No need to change existing identity keys
>     - This weakens the forward secrecy. I don't know enough about it
> to understand the consequence.
This requires huge changes in all OMEMO implementations, and there are
quite few already: https://omemo.top
Also, weakening crypto is not an idea I can become friends with :(
> 3. We stay with XEdDSA (the primitive on which X3DH relies) 
>
>     + No need to change existing identity keys
>     + This approach has been audited.
>     - Currently, no permissible implementation exists (or I couldn't
> find one at least). It's not clear when or if this will ever happen,
> and whether it will become widespread across crypto libraries. I don't
> know how these things generally go. I have only seen an issue for this
> in the LibSodium tracker (
> https://github.com/jedisct1/libsodium/issues/335
> <https://github.com/jedisct1/libsodium/issues/335> )
I guess its only a matter of time until a permissive implementation
comes along. I mean, the interest in strong crypto is there and the
Signal protocol was praised by nearly every cryptographer on the planet,
so I'm expecting independent implementations of the protocol pretty soon.

Vanitasvitae

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to