Post #3932318
2026-07-19 10:43 UTC
RE: https://infosec.exchange/@tsmreu/116806525948769324
I received feedback from a cryptography expert, who pointed out that my original trick of withholding the nonce from the server might work in practice, but it prevents a formal security proof under standard AEAD models.
So I updated the protocol: Instead of the nonce, the encryption key for the serverKey is now withheld, distributed to the trusted friends, and only sent to the server during the recovery.
So the challenge is still going, if you're still interested :)
Replies (0)
No replies.