logoalt Hacker News

danparsonsonyesterday at 11:31 PM2 repliesview on HN

https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc...

If Meta are turning it off then I guess it's reasonable to assume that there is something to turn off.


Replies

LPisGoodyesterday at 11:52 PM

Diffe-Hellman-Merkel key exchange is vulnerable to attacker-in-the-middle attacks.

Eave could just do key negotiation with Alice and separately do key negotiation with Bob. You have to use a slightly more complicated cryptographic protocol to avoid this issue.

show 1 reply
tardedmemeyesterday at 11:37 PM

How would the keys get stored in the user's private browsing window? Do they lose all chat history when they log in on a private browsing window and then close it?

show 1 reply