Let the clients handle end-to-end encryption with something zk DH/OTR/SMP.
I'm curious how they later monitored this and did other common SRE stuff. Also deployments.
Let the clients handle end-to-end encryption with something zk DH/OTR/SMP.
I'm curious how they later monitored this and did other common SRE stuff. Also deployments.
ZeroMQ also has its own experimental elliptical-curve encryption protocol now: http://curvezmq.org/ They call it experimental, but I've haven't heard anything negative about the implementation from the cryptographers, and elliptical curve crypto is well-established (it's the basis for Bitcoin's key signing, for example). Also, it's closely based on Daniel J. Bernstein's CurveCP.
As an aside, MQTT has a constrained device optimized sibling MQTT-SN, which works over UDP and supports sleepy nodes, etc. Unfortunately that one's stuck in licensing hell and does not yet have good tooling, at least last time I checked.
I gave a talk about MQTT-SN Gateway at Erlang User Conference 2013:
http://www.erlang-factory.com/conference/ErlangUserConferenc...
http://www.erlang-factory.com/upload/presentations/807/ZviMQ...