Remko,

can you please describe the concrete benefits of your approach?
The only difference I can spot is that it's more implementation work for those 
that use libsignal (which at this point in time seems to be all 
implementations) and less for libsodium (which happens to not implement many 
other parts of the protocol as well and thus require a lot of work nonetheless).

I wouldn't use neither so I don't care about that part ;)
Is there any difference from a crypto perspective that I missed? As far as I 
can tell, this is only a constant factor for any attack I can imagine, if at 
all.

Ignat

"Remko Tronçon" <[email protected]> wrote:

On 29 May 2017 at 07:53, Remko Tronçon <[email protected]> wrote:

I may have a solution to our OMEMO key agreement discussion that satisfies all 
of us.

FYI, to get some more confidence in this approach, I prototyped it using both 
libsignal and libsodium:
 
   https://github.com/remko/omemo-key-exchange

The libsignal prototype actually mimics the 2 parts of libsignal that need to 
be patched; patching the library itself should be even less work/code (but I 
couldn't find an OMEMO client for my platform to apply the changes myself).

Remko
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to