<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link xmlns:atom="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="https://tanguy.ortolo.eu/blog/feed/rss/commentaires/" />
	<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer</link>
	<language>en</language>
	<description>a blog about Debian and self-hosting</description>
	<lastBuildDate>Fri, 20 Sep 2013 16:15:00 +0000</lastBuildDate>
	<generator>PluXml</generator>
	<item>
		<title>Encryption without a certification layer is (partly) useless - Written by dolanor @ friday 20 september 2013, 16:15</title> 
		<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1379693753-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1379693753-1</guid>
		<description>Except that a shared secret could be a simple, uncomplicated password that you whisper in one&amp;#039;s ear. Saying the full fingerprint or the full public key in base64 or hexa would be less practical. 

I agree though that giving a usb key could be an easy solution though</description>
		<pubDate>Fri, 20 Sep 2013 16:15:00 +0000</pubDate>
		<dc:creator>dolanor</dc:creator>
	</item>
	<item>
		<title>Encryption without a certification layer is (partly) useless - Written by Tanguy @ tuesday 18 june 2013, 07:39</title> 
		<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371541146-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371541146-1</guid>
		<description>@Sebastian Weisgerber : Well, if you can meet someone to define or check a shared secret, you might as well exchange public keys with each other…</description>
		<pubDate>Tue, 18 Jun 2013 07:39:00 +0000</pubDate>
		<dc:creator>Tanguy</dc:creator>
	</item>
	<item>
		<title>Encryption without a certification layer is (partly) useless - Written by Sebastian Weisgerber @ tuesday 18 june 2013, 07:13</title> 
		<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371539617-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371539617-1</guid>
		<description>Authentication really matters in encryption.
But there are possibilities without certificates, to ensure the identity of the person you are talking to, or at least to prevent MitM attacks.
See for example ZRTP for voice encryption or OTR for message encryption.

With the aid of shared secrets, you can _increase_ the likeliness, that the identity is correct, but you can&amp;#039;t be 100% sure.
If someone steals your contact&amp;#039;s phone or your contact person is extorted while talking to you, third parties can still eavesdrop your communication...
=&amp;gt; At least one party knows what happened in these scenarios, which doesn&amp;#039;t help if your are the unaware one...</description>
		<pubDate>Tue, 18 Jun 2013 07:13:00 +0000</pubDate>
		<dc:creator>Sebastian Weisgerber</dc:creator>
	</item>
	<item>
		<title>Encryption without a certification layer is (partly) useless - Written by Tanguy @ monday 17 june 2013, 19:19</title> 
		<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371496762-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371496762-1</guid>
		<description>@Anonymous : Yes, there is value, I just wanted to react to the many articles saying that this or that cannot be eavesdropped, which is often simply wrong.</description>
		<pubDate>Mon, 17 Jun 2013 19:19:00 +0000</pubDate>
		<dc:creator>Tanguy</dc:creator>
	</item>
	<item>
		<title>Encryption without a certification layer is (partly) useless - Written by Anonymous @ monday 17 june 2013, 18:47</title> 
		<link>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371494823-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article104/encryption-without-certification-layer/#c1371494823-1</guid>
		<description>There *is* value in opportunistically preventing non-MITM eavesdropping.  Not as much value, but value.</description>
		<pubDate>Mon, 17 Jun 2013 18:47:00 +0000</pubDate>
		<dc:creator>Anonymous</dc:creator>
	</item>
		<title>Tanguy Ortolo - Encryption without a certification layer is (partly) useless - Comments</title> 
</channel>
</rss>