|
|
|
|
|
by devit
3911 days ago
|
|
Ouch, isn't that totally insecure? Whatever place TextSecure is getting the key from could have replaced your girlfriend key with something else and be MITMing all the traffic. The proper way to do this would be to have your girlfriend's phone display a QR code with her public key and have you scan it with your phone camera, or using NFC to transfer the public key if available. |
|
Your "proper way" requires people to actually meet before they can begin a conversation, which greatly limits usability (you couldn't even test the app without a friend sitting next to you - who would keep an app they can't even try out on their phone?).