just trying lemmy

  • 6 Posts
  • 34 Comments
Joined 2 years ago
cake
Cake day: June 3rd, 2023

help-circle





  • Interesting :)

    A few quick questions & comments:

    1. I don’t quite understand “If all users accept the introduction, a list of contacts is sent for each contact pair. These contacts are not used for messaging to prevent more than two parties from having encryption keys.” (line 66) What exactly are the “contacts”? Is it the same data as defined on line 8? Where do the encryption keys come from? Do initiators of introduction reveal encryption keys of their existing contacts?

    2. After an introduction there’s the problem that newly introduced people cannot setup secret keys in a very clean way. Because this secret keys can be computed if an attacker gets hold of the introducer, has recorded traffic and is in possession of a large enough quantum computer (which you assume in your threat model). You therefore would need some sort of ‘upgrade’ mechanism which would allow either two people to meet in person to ‘upgrade’ their secure channel. Or you could add a asymmetric key-agreement or key-exchange on top (probably post-quantum algorithm).

    3. I don’t quite get the combination of “HTTPS”, “Tor”, “symmetric crypto because of quantum computers”. Why HTTPS if Tor already provides confidentiality? HTTPS implies certificates, no? What about them?

    4. What about nonces for GCM? How do you prevent replay attacks?

    5. If you want to truly understand your protocol and get confident about it, I recommend studying something like this: https://tamarin-prover.com/ This allows you to model your protocol more formally, state your security claims and check if the protocol satisfies this claims :)



  • “Could lose”? We are long past this point. When you can chose between two parties and they try to manipulate the election as hard as they can, then that’s a zombie democracy at best. And now? The president stands above the law. He can fire people illegally. He can disable law enforcement. Democracy in the US is gone. Hopefully only temporarily. Now it’s up to people to act, take their rogue government down and repair what can be repaired.












  • I simply wonder what’s happening and expressing my frustration.

    No question - it’s good he is mobilizing people. Organization is key, and to me it looks like it’s currently lacking. I really hope Sanders can change this.

    It has been damn obvious and yet way too many people voted Trump. And, come on, it was clear Elon would be there as well. From outside the US it’s hard to understand why. It leaves me with two explanations, both of which I don’t like: either people were misinformed and/or did not understand what is going on, or they did really want it.

    Maybe you can help me understand.