Hacker News new | ask | show | jobs
by devit 3911 days ago
Yes, using a central server should be possible, but the application should ask you whether your friend is with you and if you say yes, it should use the QR code/NFC method instead (which also has the advantage of working with people you just met and haven't otherwise added to your contacts yet).

If you say no, it should clearly delineate how an attack could take place and advise you on how likely it is.