Hacker News new | past | comments | ask | show | jobs | submit login

That's more or less what TLS+pinning does. Also DNSSEC+DANE+TLS if you want to argue about that.



Yes, but it's done at a lower level, which enables a host of attacks, like the announcement says. What I'm talking about would just encrypt the payload, so none of the metadata would be encrypted (and thus preserved).

Although I guess you'd also need to specify a "reply" public key in the encrypted data, so this is becomes more of a protocol.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: