Hacker News new | past | comments | ask | show | jobs | submit login

Indeed. It's hard to come up with use cases where a chosen, long-term low entropy secret is more suitable than alternatives like:

1) Factory paired devices

2) Pairing via ephemeral key pairs with out-of-band verification of a low entropy hash/fingerprint to prevent active MITM.

3) Straight up TOFU (trust on first use) pairing (and just praying MITM doesn't happen on first use).

The only case comes to mind is one where one device, although still physically trusted, has no persistent memory at all (and so can't store any keys).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: