• Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference?

    From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Wed Sep 16 21:40:43 2026
    From Newsgroup: alt.privacy.anon-server

    Nuno,

    You realize a few methods rely on generating and exchanging a
    symmetric key in an initial step encrypted by asymmetric keys?

    That would solve the problem related to exchanging(?) a symmetric key.

    But than why use symmetric keys when you already have something that
    generates and works with a-symmetric ones ? Thats twice the work, with no benefit.

    Just think of what could happen when one of both parties "looses"
    their symetric key ? And just assume that they do not realise
    that it has happened.

    You did not answer this one though.

    What would be possible when someone else gets hold of the symmetric key ? Would he be able to MITM ?

    Would he be able to do the same with either or both the public keys ?

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nuno Silva@nunojsilva@invalid.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 00:46:53 2026
    From Newsgroup: alt.privacy.anon-server

    On 2026-09-16, R.Wieser wrote:

    Nuno,

    You realize a few methods rely on generating and exchanging a
    symmetric key in an initial step encrypted by asymmetric keys?

    That would solve the problem related to exchanging(?) a symmetric key.

    But than why use symmetric keys when you already have something that generates and works with a-symmetric ones ? Thats twice the work, with no benefit.

    Efficiency of computation, smaller complexity.
    --
    Nuno Silva
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Librarian2025@librarian2025@cock.li to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 01:12:10 2026
    From Newsgroup: alt.privacy.anon-server


    "R.Wieser" <address@is.invalid> writes:

    Gab,

    Why though? There is no magical vulnerability in symmetric
    encryption.

    You're correct, there is nothing magical about it.

    Asymmetric encryption solves key distribution problem,
    nothing else.

    Just think of what could happen when one of both parties "looses" their symetric key ?

    I'm pretty sure they then would exchange keys again. Same as they've
    done before and same as they would have to do if one of them lose secret
    key. The process of exchanging keys would be different, of course, but
    not necessarily "worse" than in case of asymmetric encryption.

    And just assume that they do not realise that it has
    happened.

    We can "just assume" a lot of things. Let's assume that one of them lost
    their secret key and they lost the email of the other party. So now
    they can't access their previous correspondence, and they don't know
    where to write to re-establish communication. Now what?

    Regards,
    Rudy Wieser
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 09:38:13 2026
    From Newsgroup: alt.privacy.anon-server

    Nuno,

    You realize a few methods rely on generating and exchanging a
    symmetric key in an initial step encrypted by asymmetric keys?
    ...
    But than why use symmetric keys when you already have something that
    generates and works with a-symmetric ones ? Thats twice the work,
    with no benefit.

    Efficiency of computation, smaller complexity.

    You do seem to have little context awareness.

    Your answer is in regard to using only one encryption method (likely the symmetric key one). Your own "You realize" talks about using *both*
    methods in the same program.

    So, again : why use a symmetric key when you already have generated and used an a-symmetric one - just so you could safely get that symmetric key to some other party ?

    Just think of what could happen when one of both parties "looses"
    their symetric key ? And just assume that they do not realise
    that it has happened.

    I'm still missing an answer to this question though. :-|


    I get the feeling that you have no idea how to defend your stance that the usage of symmetric encryption is equal to that of a-symmetric encryption.

    In that case we should end our conversation sooner rather than later.

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 09:46:51 2026
    From Newsgroup: alt.privacy.anon-server

    Librarian2025,

    Just think of what could happen when one of both parties "looses"
    their symetric key ?

    I'm pretty sure they then would exchange keys again.

    Thats not what I asked.

    We can "just assume" a lot of things.

    Ah yes, the famous whataboutism.

    Try to answer the question. If you can't than maybe just keep your mouth shut.

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nuno Silva@nunojsilva@invalid.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 10:32:21 2026
    From Newsgroup: alt.privacy.anon-server

    On 2026-09-17, R.Wieser wrote:

    Nuno,

    You realize a few methods rely on generating and exchanging a
    symmetric key in an initial step encrypted by asymmetric keys?
    ...
    But than why use symmetric keys when you already have something that
    generates and works with a-symmetric ones ? Thats twice the work,
    with no benefit.

    Efficiency of computation, smaller complexity.

    You do seem to have little context awareness.

    Your answer is in regard to using only one encryption method (likely the symmetric key one). Your own "You realize" talks about using *both* methods in the same program.

    So, again : why use a symmetric key when you already have generated and used an a-symmetric one - just so you could safely get that symmetric key to some other party ?

    Because the asymmetric encryption used to exchange the symmetric key is
    more expensive than the symmetric encryption, so in a longer exchange
    you do asymmetric encryption at the beginning, to establish the key for
    the cheaper symmetric encryption that takes place for the rest of the conversation/exchange.

    (See SSL and TLS.)

    Just think of what could happen when one of both parties "looses"
    their symetric key ? And just assume that they do not realise
    that it has happened.

    I'm still missing an answer to this question though. :-|


    I get the feeling that you have no idea how to defend your stance that the usage of symmetric encryption is equal to that of a-symmetric
    encryption.

    That's not my stance.

    In that case we should end our conversation sooner rather than later.

    Regards,
    Rudy Wieser


    --
    Nuno Silva
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 19:12:10 2026
    From Newsgroup: alt.privacy.anon-server

    Nuno,

    So, again : why use a symmetric key when you already have generated and
    used an a-symmetric one - just so you could safely get that symmetric key
    to some other party ?

    Because the asymmetric encryption used to exchange the symmetric key is
    more expensive than the symmetric encryption, so in a longer exchange
    you do asymmetric encryption at the beginning, to establish the key for
    the cheaper symmetric encryption that takes place for the rest of the conversation/exchange.

    And so you have drifted off from how to use symmetric encryption keys for exchange of multiple messages (ref: hermes suggested MycroCrypt program) to
    a so-called session-encryption key - normally with a rather short lifespan.

    But you have a point, I did not think of doing it that way.

    Just think of what could happen when one of both parties "looses"
    their symetric key ? And just assume that they do not realise
    that it has happened.

    And I'm *still* missing an answer to this question.

    I get the feeling that you have no idea how to defend your stance that
    the usage of symmetric encryption is equal to that of a-symmetric
    encryption.

    That's not my stance.

    Than what /is/ your stance ?


    But, in a nutshell :

    The security of a symmetric key fully depends on how often you replace it.

    An a-symmetric public key doesn't have that vulnerability.

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Librarian2025@librarian2025@cock.li to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 13:54:35 2026
    From Newsgroup: alt.privacy.anon-server


    "R.Wieser" <address@is.invalid> writes:

    Librarian2025,

    Just think of what could happen when one of both parties "looses"
    their symetric key ?

    I'm pretty sure they then would exchange keys again.

    Thats not what I asked.

    Well, that's what I answered.

    We can "just assume" a lot of things.

    Ah yes, the famous whataboutism.

    It was not me who started with "just assume..."

    Try to answer the question. If you can't than maybe just keep your mouth shut.

    I'm not obligated to only give you answers that you like.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Thu Sep 17 22:11:30 2026
    From Newsgroup: alt.privacy.anon-server

    Librarian2025,

    Just think of what could happen when one of both parties
    "looses" their symetric key ?

    I'm pretty sure they then would exchange keys again.

    Thats not what I asked.

    Well, that's what I answered.

    And with it you've shown to me you're dishonest.

    Goodbye.

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Yamn3 Remailer@noreply@mixmin.net to alt.privacy.anon-server on Thu Sep 17 21:15:36 2026
    From Newsgroup: alt.privacy.anon-server


    On 9/17/2026 12:54 PM, Librarian2025 wrote:

    "R.Wieser" <address@is.invalid> writes:

    Librarian2025,

    Just think of what could happen when one of both parties "looses"
    their symetric key ?

    I'm pretty sure they then would exchange keys again.

    Thats not what I asked.

    Well, that's what I answered.

    We can "just assume" a lot of things.

    Ah yes, the famous whataboutism.

    It was not me who started with "just assume..."

    Try to answer the question. If you can't than maybe just keep your mouth
    shut.

    I'm not obligated to only give you answers that you like.


    Touche!

    That was a good comeback!
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nuno Silva@nunojsilva@invalid.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Fri Sep 18 11:16:53 2026
    From Newsgroup: alt.privacy.anon-server

    On 2026-09-17, R.Wieser wrote:

    Nuno,

    So, again : why use a symmetric key when you already have generated and
    used an a-symmetric one - just so you could safely get that symmetric key >>> to some other party ?

    Because the asymmetric encryption used to exchange the symmetric key is
    more expensive than the symmetric encryption, so in a longer exchange
    you do asymmetric encryption at the beginning, to establish the key for
    the cheaper symmetric encryption that takes place for the rest of the
    conversation/exchange.

    And so you have drifted off from how to use symmetric encryption keys for exchange of multiple messages (ref: hermes suggested MycroCrypt program) to a so-called session-encryption key - normally with a rather short lifespan.

    But you have a point, I did not think of doing it that way.

    I think at one point in the thread the usefulness of symmetric
    encryption was questioned, hence why I mentioned that.


    Just think of what could happen when one of both parties "looses"
    their symetric key ? And just assume that they do not realise
    that it has happened.

    And I'm *still* missing an answer to this question.

    I get the feeling that you have no idea how to defend your stance that
    the usage of symmetric encryption is equal to that of a-symmetric
    encryption.

    That's not my stance.

    Than what /is/ your stance ?


    If I have to have a stance and make it public on anything you choose to
    point out in the context of threads I'm replying to, that's a game I
    don't want to play.

    But, in a nutshell :

    The security of a symmetric key fully depends on how often you replace it.

    An a-symmetric public key doesn't have that vulnerability.

    Oh, but it does have similar weaknesses depending on size and the
    advance of computing machinery, and making them age-limited is a thing
    that *is* done too.


    Regards,
    Rudy Wieser


    --
    Nuno Silva
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From R.Wieser@address@is.invalid to alt.privacy.anon-server,comp.mobile.android,alt.comp.freeware on Fri Sep 18 15:03:17 2026
    From Newsgroup: alt.privacy.anon-server

    Nuno,

    I think at one point in the thread the usefulness of symmetric
    encryption was questioned, hence why I mentioned that.

    Not by me. I *did* however question its application :

    [quote=me]
    MicroCrypt is a multi-purpose symmetric encryption app for mobile and desktop.

    Symmetric ? That to me means its disqualified.
    [/quote]

    I get the feeling that you have no idea how to defend your stance
    that the usage of symmetric encryption is equal to that of
    a-symmetric encryption.

    That's not my stance.

    Than what /is/ your stance ?

    If I have to have a stance and make it public on anything you choose
    to point out in the context of threads I'm replying to, that's a game
    I don't want to play.

    *You* say that thats not your stance , but when I than ask what that stance
    is you don't want to tell ? Thats odd ...

    But, in a nutshell :

    The security of a symmetric key fully depends on how often you replace
    it.

    An a-symmetric public key doesn't have that vulnerability.

    Oh, but it does have similar weaknesses depending on size and the
    advance of computing machinery, and making them age-limited is a
    thing that *is* done too.

    Weaknesses that are equal or surpass that of a symmetric encryption ?

    And Nuno, I've been *trying* to compare the security of the usage of the encryption *keys*. Can you stay on that subject ?

    And to re-re-re-repeat myself :

    [quote]
    Just think of what could happen when one of both parties "looses"
    their symmetric key ? And just assume that they do not realise
    that it has happened.
    [/quote]

    I'm *still* missing an answer to this question. :-(

    Or, bluntly said: I'm getting the feeling you want to ignore the, to me, obvious.

    You may do that ofcourse, but you're getting tiresome. You want to put your POV (stance?) forward and have me respond to it ? Than I expect the same
    from you.

    Regards,
    Rudy Wieser


    --- Synchronet 3.22a-Linux NewsLink 1.2