46 karma · joined November 2, 2021
There are (were) many smaller groups that use private channels. It is also how me and my first bf and some of my friends ended up talking.
And still no e2ee, after all these years.
Never doing any buissness with ms again.
You previously claimed that this will cost an average of 2^64 key generations, but this is just to find two pks that cause collisions in the 128 bit output space - two pks which most likely are not used by any of their users (which are what, around 2^20 atm?) I would be interested in an updated estimate of how long such a collision would take when keeping this in mind.
I can't see how the server can create pk' just with a collision attack in this case if pk is not controlled by them. Looks to me like they need a 2nd preimage attack.
But maybe I am just stupid.
The only thing that matters here is 2nd preimage resistance, which still has 128 bits of security.
As for /dev/random, I only mentioned it because your advice is outdated.
Some other comments: yes, if you do not provide a password then your key won't be encrypted and anyone in possesion of your phone will be able to extract it. Seems normal to me. As for pbkdf/sha, meh, nothing can replace a good password, but sure, argon2 would be better but this seems like an extremely minor issue, kinda like complaining about how signal uses aes128 instead of 256.
It is allowed.
This attack is unwaranted and without substance or explanation.
I can't see anything anticapitalist here.