Hacker News new | past | comments | ask | show | jobs | submit login

Yeah, the key delivery is the hardest part if you are privacy focused. Signal and Whatsapp have a screen, where you can generate a QR code, and use that to verify that you and your contact have exchanged keys without a man in the middle attack.



I wish browser would do something similar with their WebRTC stack. Something that shows independently of the site (out of its execution context) which keys are used and allow for an easy comparison of them independently. But i don't know of such functionality being there yet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: