[messaging] PKI is dead
justin.king-lacroix at cs.ox.ac.uk
Fri Jan 23 14:49:13 PST 2015
I think "is" and "should be" have been conflated. (Unfortunately -- PKI
needs to die, I agree.)
Is PAKE really the way to go, though? Having servers store raw (as opposed
to salt-hashed) credentials feels like a mistake.
On 23 January 2015 at 09:57, U.Mutlu <for-gmane at mutluit.com> wrote:
> SSL certificate stuff (ie. PKI) is IMO dead. NSA killed it.
> Back to the roots: hashed pw over MITM-safe sessions (SRP, SPEKE etc, ie.
> Messaging mailing list
> Messaging at moderncrypto.org
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Messaging