Skip to content

Comment on Signal and Giphy

Comments

It would be interesting for services to publish a public encryption key, so the signal client could encrypt the payload with that.

However, that has very limited usefulness, so I don't see it happening soon.

That's more or less what TLS+pinning does. Also DNSSEC+DANE+TLS if you want to argue about that.

Yes, but it's done at a lower level, which enables a host of attacks, like the announcement says. What I'm talking about would just encrypt the payload, so none of the metadata would be encrypted (and thus preserved).

Although I guess you'd also need to specify a "reply" public key in the encrypted data, so this is becomes more of a protocol.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.