I would like to see a security analysis. The code phrases seem ludicrously short to me …
I would like to see a security analysis. The code phrases seem ludicrously short to me …
I admit I'd rather see a longer default passphrase too, but fortunately this is adjustable on the sender's end of the connection, so you can choose a longer one if you'd like.
Edit: to be more specific: 32 bits means that an attacker has a 1 / 4294967296 chance of guessing your password. They do not get multiple tries, because that's not how PAKE works. It's akin to agreeing with someone that you will meet in the park and exchange a short secret phrase to prove your identities, whereupon you will exchange GPG keys with each other or whatever. You don't need 128 bits of security for the "meeting in the park" exchange, any short unguessable phrase will do.
One attacker has that chance for one transfer.
But if the service is popular, then it's perfectly feasible that typing in som random choice intercepts some arbitrary file belonging to someone.
The appropriate use of "bit" here made me smile.
If you guess wrong, the machines trying to do the transfer see an error.