encrypted telnet

Hal 74076.1041 at CompuServe.COM
Fri Apr 23 15:36:29 PDT 1993


I missed the context because my mailbox overflowed, but Eric mentioned
Diffie-Hellman key exchange.  If the need is for a one-shot quick-n-dirty
session key exchange (as for the audio talk program John Gilmore mentioned)
an alternative is to do a quick PGP keygen, send the session key across
using the PGP key, then destroy the PGP key.

The only reason I mention this is that it can be done in a couple of minutes
with existing tools tomorrow, if you need it.  Eric is right that if you
are designing something from scratch DH is often more appropriate (although
PK's allow for authentication if you have a trusted signature, preventing
spoofing attacks).

Hal







More information about the cypherpunks-legacy mailing list