Hi Riba, > The attack is described in [1] and boils down to the following: > While I think that because of the noticability the possible damage is very limited, I kind of agree that it is not acceptable by design. One argument for 3DH might be its full deniability, which X3DH does not provide, though.
Thanks, good to know. > X3DH does not rely on XEdDSA, it relies on any digital signature. Thanks for these insights. This seems to confirm my understanding so far. > If all else fails, there is always the possibility to have both a X25519 > and a Ed25519 key Right, but that would leave 2 keys to be managed and authenticated, wouldn't it? Which wouldn't be very nice from a usability POV. > but I don't really think the conversion specified in [2] qualifies as "crypto" Good to know. Unfortunately, the public key conversion part relies on low level operations AFAICT, so you'd need support from a library for practical reasons, wouldn't you? thanks, Remko
_______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
