Hacker News new | ask | show | jobs
by mike-cardwell 3998 days ago
It's not that I want to keep a key for a long time, it's that I have several different clients and I want to share whatever key I'm currently using across them. That way I only have to stick the fingerprint of one OTR key on my business cards.
1 comments

why not then print a shared secret on your business card, and use the socialist millionaires problem (https://en.wikipedia.org/wiki/Socialist_millionaire)?

edited, added some explanation: (since there's a time span between handing out your card and verifying the FP, in which your key might have get compromised... and thus the one who received the card cannot verify whether you really got compromised and needed to update your key, or an attacker intercepted with a new key)...