Conversation
Notices
-
lnxw48a1 (lnxw48a1@nu.federati.net)'s status on Tuesday, 31-Jan-2023 22:28:04 EST lnxw48a1
#Session seems to be a usable messenger, but its current incarnation lacks "perfect forward secrecy":{https://en.wikipedia.org/wiki/Forward_secrecy}. See https://getsession.org/session-protocol-explained and https://getsession.org/blog/session-protocol-technical-information
> PFS means that if long-term keys for a given conversation are compromised, only a small amount of recent messages can be decrypted. However, under typical circumstances, the only way long term keys can be compromised is through full physical device access — in which case an attacker could simply pull the already-decrypted messages from the local database. As is often said in the infosec community, physical access is total access.
I understand this, but maybe y'all can reinstate PFS and not store messages unencrypted. So that (for example) a police officer on a fishing expedition cannot obtain your full history and content of conversations by seizing your phone.