"WireOver uses what we believe are the most appropriate, safe, up-to-date, peer-reviewed crypto primitives, implementations, and parameters [...] Fingerprint Algorithm: MD5"
I fear this page was written with a straight face :(
I fear this page was written with a straight face :(
What would you prefer personally: (1) MD5 fingerprint for convenience AND entire peer public key base64 available if you really want; vs (2) just a longer SHA-256 fingerprint.
On the server-side, we don't store the authentication
code in plaintext. We hash it with PBKDF2 / SHA-256,
salt it, then store it.