Skip to content

Require ephemeral encryption keys? #194

@jogu

Description

@jogu

As per discussion on today's WG call, we should consider mandating that encryption keys are ephemeral, as that's only kind of hinted at in VP but seems like a good practice and improves security by preventing responses from one session being injected into a different session.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions