Hacker News new | ask | show | jobs
by throwaway415415 2684 days ago
The server can still bruteforce it though right?
1 comments

(author of magic-wormhole here)

Nope, the server gets no more power than a random network attacker. The codes are single-use, enforced by PAKE, so an attacker (or the server) gets at most one chance to guess the code for any single execution of the program.