|
|
|
|
|
by gefhfffh
1624 days ago
|
|
How resistant to MITM is it though? Currently, verification seems to work on a session basis and not just per user, which makes it very tedious to have everything verified e.g. a group chat. If it is not almost impossible given peoples sessions change with time. Add a new session in the browser -> meet every contact to verify their sessions with your new browser session?
Doesn't seem very practical, and reminds me of the old times in [matrix]. This opens room for MITM attacks |
|
Also you don't have to meet with everyone to verify new keys, you can just use a known good key for that. Essentially, if you want 100% security by comparing keys in a meetup, you can do that once and then use that known good channel to verify every new key.
In reality, cryptonerds will be happy to verify every single new key, everyone else will never bother to even open the key signature view and I will get a confused call should it be opened by accident.
> This opens room for MITM attacks
Yes, in your constructed strawman world xmpp is prone to MITM. In reality it's equally or less prone than its competitors.