Hi Riba,

> The attack is described in [1] and boils down to the following:
> While I think that because of the noticability the possible damage is
very limited, I kind of agree that it is not acceptable by design. One
argument for 3DH might be its full deniability, which X3DH does not
provide, though.

Thanks, good to know.

> X3DH does not rely on XEdDSA, it relies on any digital signature.

Thanks for these insights. This seems to confirm my understanding so far.


> If all else fails, there is always the possibility to have both a X25519
> and a Ed25519 key


Right, but that would leave 2 keys to be managed and authenticated,
wouldn't it? Which wouldn't be very nice from a usability POV.

>  but I don't really think the conversion specified in [2] qualifies as
"crypto"

Good to know. Unfortunately, the public key conversion part relies on low
level operations AFAICT, so you'd need support from a library for practical
reasons, wouldn't you?

thanks,
Remko
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to