[messaging] Google End-to-End plans on using key directories with a CT-like verification protocol
Tony Arcieri
bascule at gmail.com
Thu Aug 28 15:20:43 PDT 2014
On Thu, Aug 28, 2014 at 3:17 PM, David Leon Gil <coruus at gmail.com> wrote:
> The issue is that usernames are extremely guessable. I think that
> Joseph Bonneau had some stats on this in his thesis.
>
> It can be made more different by using a largish scrypt instance, but
> it's still going to be easy to guess (at least) 50% of email
> addresses.
The method doesn't have to be perfect, or even good. It just needs to be
more difficult than the existing, plentiful methods of email address
harvesting.
--
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/messaging/attachments/20140828/934c8d59/attachment.html>
More information about the Messaging
mailing list