|
|
|
|
|
by XMPPwocky
2194 days ago
|
|
Hi. I'm a malicious server. When a client requests the public key from me, I give them a fake one- not the one present on the air-gapped PC, my own key. I then decrypt their vote, inspect it, and re-encrypt it with the real key before sending it off to the air-gapped server. Does this work? How do you detect it? And what's your threat model? |
|