Re: [OTR-dev] purpose of hash commitment in OTR authenticated key exchange

2011-03-16 Thread Ian Goldberg
On Wed, Mar 16, 2011 at 04:37:37PM +0100, Stefan Schönleitner wrote: > Hi, > > I was wondering what the exact purpose of the Diffie-Hellman hash commitment > in the OTR authenticated key exchange is. > The paper "Improved User Authentication in Off-The-Record Messaging" says > that the "initial co

[OTR-dev] purpose of hash commitment in OTR authenticated key exchange

2011-03-16 Thread Stefan Schönleitner
Hi, I was wondering what the exact purpose of the Diffie-Hellman hash commitment in the OTR authenticated key exchange is. The paper "Improved User Authentication in Off-The-Record Messaging" says that the "initial commitment is used to ensure that neither party can base their choice of g^x on the