|
|
|
|
|
by eru
1737 days ago
|
|
Very neat: > 1.2.4. Messages are Authenticable, but not Opposable. > All Pest messages are authenticable -- a station will only process a message if it carries a valid signature from a peer (though in some cases, the message may not have been authored by that peer.) > However, they are also repudiatable (i.e. non-opposable) -- since all packet signatures are produced with symmetric keys, the recipient of a message cannot, at any point in time, prove to a third party that he was not in fact the author of that message. |
|
So basically there is intentionally no way to prevent message forgery by the recipient. Why?
Also tbh. how can I trust a person who in 2021 still hasn't understood that/why HTTPS is important for security even if you only provide read only content with making proper crypto/security decisions?