Menu

📰
0

Does a short public key fingerprint is at risk if there is central registry?

Reddit r/cryptography·u/sneko7·about 1 month ago
#x1yXHavS
Reading 0:00
15s threshold

Does a short public key fingerprint is at risk if there is central registry? Hi, my question may be stupid but I see a lot of apps having fingerprint verification with 60 numerics or using a QR code to verify the other user. From what I see around me, just a few are really checking others fingerprint (within Signal, WhatsApp...), probably because people act as TOFU (they wanted to talk to someone so unlikely a hack has been done in the meantime). Now in the context of a company, security can be taken more seriously and it could be "mandatory" in an E2EE application to check others identity. But when people are spread in different locations the QR code is not that easy, same about comparing 60 numerics. I'm wondering if this company could use a shorter fingerprint like \`465 584\`?…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More