Hacker News new | ask | show | jobs
by palata 1364 days ago
> and things like the server-assisted initial key exchange are both bolted-on and often omitted from security analysis in a way that I find very dubious.

You mean the Extended Triple Diffie-Hellman? What do you mean by "bolted-on"? Would you consider it "bolted-on" too, if it was just a normal Diffie-Hellman (hence not asynchronous)?