You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
π€ How could I not implement ECIES-E2EE with age for so long! MITM πΆπ»ββοΈ
Tip
Piping-path should not expose host pubkey, use one-way hash. MITM at piping server will see the requesting client's ephemeral pubkey in the age header. Post-quantum, having two pubkeys = broken ECDH. So let MITM have only
hash of one pubkey (dictionary attack possible if pubkey is in DNS...risk-convenience trade-off post-quantum) and the other pubkey. If the first hash is preimage resistant (and no dictionary attack), this may be safe post quantum.
only one pubkey (session key).
TBD: Can we go hybrid (Post-Quantum + ECIES)?! May be not right now until DNS, as pubkey will be too big. Also, PQ is not available in age for legacy systems: 22.04 Ubuntu for example.
π€ How could I not implement ECIES-E2EE with
agefor so long! MITM πΆπ»ββοΈTip
Piping-path should not expose host pubkey, use one-way hash. MITM at piping server will see the requesting client's ephemeral pubkey in the
ageheader. Post-quantum, having two pubkeys = broken ECDH. So let MITM have onlyTBD: Can we go hybrid (Post-Quantum + ECIES)?! May be not right now until DNS, as pubkey will be too big. Also, PQ is not available in
agefor legacy systems: 22.04 Ubuntu for example.