[messaging] Are we pursuing real solutions for security?

elijah elijah at riseup.net
Tue Mar 11 13:31:23 PDT 2014


On 03/11/2014 03:33 AM, Tony Arcieri wrote:

> I don't think these solutions are providing effective security. I feel
> we need to start from the real needs of real users, and work backwards.

For me, the goal needs to be zero-click encryption, as Schneier has
recently called it, so I get very uncomfortable with any discussion of
fingerprints or even SAS. That said, I recently created a ton of ssh
keys for testing purposes and I was reminded of the beauty of Adrian
Perrig's randomart hash visualization:

+--[ RSA 2048]----+
|  . . .   .      |
| . . . E o       |
|.       + o      |
|..  .  o * .     |
|.. o    S o      |
|. o  ... .       |
| . . oo          |
|    o..          |
|     .o+.        |
+-----------------+

-elijah


More information about the Messaging mailing list