monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Re: netsync transport encryption?


From: Cem Karan
Subject: Re: [Monotone-devel] Re: netsync transport encryption?
Date: Wed, 25 Oct 2006 11:06:29 -0400


In short, you would lose authentication and guarantees of privacy if you don't have each other's public keys, but it shouldn't affect the connection in any way, even for anonymous access.

You totally ignore man-in-the-middle attacks, don't you?

I'm sorry, I was unclear in what I meant when I wrote that. When I wrote "...but it shouldn't affect the connection in any way, even for anonymous access.", I meant from a code point of view. The Monotone source will see the (fake/anonymous/whatever you want to call it) public keys, and use them the same way as if you had real keys and real authentication. I make no guarantees about security without authentication! ;)

Thanks,
Cem Karan




reply via email to

[Prev in Thread] Current Thread [Next in Thread]