Emile Cormier

Results 281 comments of Emile Cormier

SPAKE2+ seems to be a potential successor to SRP, but I wouldn't be comfortable adopting it at this point for the following reasons: * The IETF draft leaves too much...

@meejah You're correct that that Magic Wormhole uses balanced SPAKE2. I've included Magic Wormhole information under my SPAKE2+ heading because the author who wrote the SPAKE2 Python/Javascript implementations also provided...

@meejah > That is, they know your email and send you a new one-time password every time you log in from a new computer. This sounds interesting, but again, our...

@oberstet The frontend team decided to use Thruway.js due to the better integration with Angular. It might be possible for us to customize the AUTHENTICATE response on the frontend with...

The IRTF Crypto Forum Research Group is in the process of selecting one (or more) PAKEs: - https://mailarchive.ietf.org/arch/msg/cfrg/-J43ZsPw2J5MBC-k8y6--kJJtZk - https://mailarchive.ietf.org/arch/msg/cfrg/tjyjNk-GODs_wMwPk3SvPH4J76I I hope this leads to a standard with robust implementations...

Nice write-up here of PAKEs, SRP, and a new one named OPAQUE: https://blog.cryptographyengineering.com/2018/10/19/lets-talk-about-pake/

> Using multi-factor designators like scram-totp won't work, as we now allow to have suffix parts designate algo variants, like scram-sha256. Over in #135, @meejah and I are now in...

> A client library should maintain a ref count (like AutobahnJS and AutobahnPython already do), and only issue a UNSUBSCRIBE message when the last handler was removed. My upcoming C++...

On the client side, if you're dealing with multiple subscriptions to the same topic, then you _must_ have some kind of collection to keep track of all the handlers associated...

Thanks, I understand now. Under [Invocation ERROR](https://github.com/tavendo/WAMP/blob/master/spec/basic.md#invocation-error) and [Call ERROR](https://github.com/tavendo/WAMP/blob/master/spec/basic.md#call-error) it says: > `Details` is a dictionary with additional error details. which is what lead to my confusion. Perhaps those...