-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
lack of checking when Bob knows Alice's FP #44
Comments
Just trying to understand by rephrasing here: |
to fix this issue isn't it sufficient to write: "a) If bob's device already verified that Alice's e-mail address is associated with |
The approach sounds good. I would use a different term than 'verified'. The other question for me is if we want to explicitely ask the user to verify that the email address matches the person they are talking to. I think we don't neet to but should make it very obvious who one is verifying by highlighting the email address during the process. |
In step 4b) Bob just sends back his key, but he does not check that the email received is the same as the one he had associated to the value
Alice_FP
he had stored. Doesn't this open the door to an attack? As long as I know Alice's FP I can get Bob to engage. Am I missing something?The text was updated successfully, but these errors were encountered: