This commit is contained in:
Joey Hess 2016-12-06 16:55:53 -04:00
parent bb5168e894
commit 60f4b1cf36
No known key found for this signature in database
GPG key ID: C910D9222512E3C7

View file

@ -123,6 +123,10 @@ so won't want to type that in. Need discovery.
for Bob to confirm he's ready to finish pairing, this will fail,
because Bob won't get to that point if the authtoken is intercepted.
Check out
<https://en.wikipedia.org/wiki/Password-authenticated_key_agreement>
for more MITM resistance.
## local lan detection
At connection time, after authentication, the remote can send