GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    scriptjunkie (sj@social.scriptjunkie.us)'s status on Thursday, 16-Jan-2025 04:28:46 JSTscriptjunkiescriptjunkie
    in reply to
    • Dan Goodin

    @dangoodin That post totally misunderstands signature schemes and how they are used.
    https://social.scriptjunkie.us/@sj/113834017119054709

    In conversationThursday, 16-Jan-2025 04:28:46 JST from social.scriptjunkie.uspermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: social.scriptjunkie.us
      scriptjunkie (@sj@social.scriptjunkie.us)
      from scriptjunkie
      Attached: 1 image The "Don't Use Session (Signal Fork)" post shows a tragic lack of understanding of basic cryptographic primitives and Session's protocol. The post claims the signature validation code of a message "reduced the utility of Ed25519 to that of a CRC32". But immediately following the quoted blob, you'll see that the message sender public key that validated the message is used to identify the sender. If you try to "forge" a message with your own key, it won't show up as from someone else or in their conversations, it will show up as from you! That's the literal basic use case of a signature. It proves who it came from. While a CRC32 could be calculated for any message, even with a forged sender. This shows the post completely misses the point of asymmetric cryptography signature schemes. The post may be correct with the AES encryption to public keys, however, so I'd still regard both Session and the post with suspicion until a more thorough analysis can be done. https://github.com/session-foundation/session-android/blob/75e2b87278cc378e21b77b27fa1a2aa773d25520/libsession/src/main/java/org/session/libsession/messaging/sending_receiving/MessageDecrypter.kt#L58-L62
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.