Hacker News new | ask | show | jobs
by hurin 4086 days ago
Exactly, you have to exchange public-keys via another method - which is also potentially vulnerable.
2 comments

But all forms of exchange are potentially vulnerable, the point of using multiple channels for authentication is to increase the challenge-space for potential attackers. Indeed the chief benefit of public key encryption is that the key can be exchanged over a multitude of channels and a compromise of just some of them does not jeopardize the entire operation. Perhaps we need more authentication systems where this is made implicit, with trust based on the number of different mediums the key is transferred over (or the number of different third party signers).
Use keybase.io