|
|
|
|
|
by blamestross
769 days ago
|
|
I'm not convinced requirements 3 and 4 are actually needed. 3) make internal state not useful to the attacker. 4) assuming the ciphertexts won't leak seems silly. Might as well hand them out. Which leads to what they call "trial decryption" to be a better solution. If you are that worried about the scalability of your whistleblower protocol at that level, we are trying to solve the wrong problem. |
|