They say key exchange is by Diffie-Hellman, and authentication is by validating fingerprints.
I fear this page was written with a straight face :(
What would you prefer personally: (1) MD5 fingerprint for convenience AND entire peer public key base64 available if you really want; vs (2) just a longer SHA-256 fingerprint.
On the server-side, we don't store the authentication
code in plaintext. We hash it with PBKDF2 / SHA-256,
salt it, then store it.To mitigate MITM attacks, ask your peer for their public key fingerprint using something other than WireOver: phone, SMS, email, PGP email - whatever you're comfortable with. That's your "second factor of authentication".
Your approval is cached so you only need to do it once.
We'll better explain this on the website.