Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The threat model also suggests that you verify key fingerprints manually if you are concerned about MITM.


Yeah, I guess verifying the full length of the fingerprint would mitigate that, and not doing that exposes you to a MITM attack anyway. Not much less secure than exchanging the keys directly, then, you are right.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: