Toot

Written by Robert Gützkow on 2025-01-16 at 06:19

@sj @dangoodin how would you know whether or not the public key belongs to Alice? Usually in protocols you would have a handshake at the beginning where you'd verify that the sender can sign a message properly. The public key of the sender would have to be known prior and out of band (think certificates like in TLS). Here they just place the public key in the message and use it for the signature verification. As far as I can see, there is nothing in the snippet ensuring that the public key belongs to the sender we are expecting to communicate with.

=> More informations about this toot | View the thread | More toots from robertguetzkow@infosec.exchange

Mentions

=> View sj@social.scriptjunkie.us profile | View dangoodin@infosec.exchange profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113836581700365875
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
224.084512 milliseconds
Gemini-to-HTML Time
0.412603 milliseconds

This content has been proxied by September (3851b).