[messaging] Unlinkable rendezvous via human-sized keys (was: Re: Human sized keys)

> FWIW, here's a thing I did years ago:
> http://www.apache-ssl.org/apres.pdf

Nice!, definitely anticipates some of the Pond / PANDA stuff.

Like PANDA, Apres authenticates an online rendezvous with an "introduction
secret" agreed between users:

One protocol [...] would be for each person to choose two words. Both
people then remember (or write down) all four words. Assuming people make
some effort to choose from a wide vocabulary, we could safely assume around
12 bits of entropy in each word, giving a total entropy of 48 bits.

Watson and I are discussing a different approach: have users exchange ECDH
keys or fingerprints instead of exchanging introduction secrets directly.
 Then calculate the "introduction secret" via ECDH.  These ECDH public
values could be static and nonsecret, so should be easier to deal with
(could be printed on a business card, corroborated with online lookup, etc.)

