Proposal: permanent passwords
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
Permanent passwords =================== We could make IP + password play the same role as noderefs do now. They must be exchanged in both directions, but if you have both passwords you can initiate a connection and noderefs will be exchanged. This should be a reasonably simple protocol: Just send a packet which includes proof that you have both passwords (a hash), and a random nonce for crypto setup. This is no more work than out of band verification. However, you cannot broadcast your IP + password and wait for people to contact you, which is a distinct advantage in out of band verification: All contacts must be arranged strictly in advance. And it's not very newbie friendly either. Dependancies ------------ UP&P isn't necessary if the exchange is conducted in real time. If it is almost-real-time then UP&P may be helpful. Attacks ------- If the attacker can guess both passwords he can MITM, identify traffic, etc. _______________________________________________ Tech mailing list [email protected] http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF7M3VA9rUluQ9pFARAht0AJ9oueUBxrSSCmFqrSzgT/NuI+5bpwCfUZ1/ fxlfzvt61GQksOhr3qqa4XQ= =pXbZ -----END PGP SIGNATURE-----