<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[In an E2EE system, how does Alice know what Bob&#x27;s public key is?]]></title><description><![CDATA[<p>In an E2EE system, how does Alice know what Bob's public key is?</p><p><a href="https://mastodon.gamedev.place/tags/cryptography" rel="tag">#<span>cryptography</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/acad8967-a485-4924-8409-5c4c0f720f99/in-an-e2ee-system-how-does-alice-know-what-bob-s-public-key-is</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 00:05:36 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/acad8967-a485-4924-8409-5c4c0f720f99.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Apr 2026 16:23:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to In an E2EE system, how does Alice know what Bob&#x27;s public key is? on Wed, 08 Apr 2026 17:06:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghosttie%40mastodon.gamedev.place">@<span>ghosttie</span></a></span> <span><a href="/user/dacmot%40sunny.garden">@<span>dacmot</span></a></span> I think you need a second communication channel. And something to corroborate that multiple channels are controlled by the same person. The most surefire way is to meet in person and confirm the keys. I don't think there's a purely technical way to solve this without putting trust into some central authority. It's inherently a social problem.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Zoarial94/statuses/116370175881864636</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Zoarial94/statuses/116370175881864636</guid><dc:creator><![CDATA[zoarial94@infosec.exchange]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:06:06 GMT</pubDate></item><item><title><![CDATA[Reply to In an E2EE system, how does Alice know what Bob&#x27;s public key is? on Wed, 08 Apr 2026 17:04:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghosttie%40mastodon.gamedev.place">@<span>ghosttie</span></a></span> one way would be to meet in person.</p><p>In a system like Signal, it would be built in to the user ID. For things like PGP/GPG, websites, or developer signing key, there are multiple mechanisms to verify the key identity. You can use a web of trust (WOT) or keyrings, certificate authorities like DigiCert/Let's Encrypt, or MS/Google/Apple issuing signing keys.</p><p>Note that none of those methods are perfect, and a bad actor could still manage to impersonate someone else. But it makes it significantly harder.</p>]]></description><link>https://board.circlewithadot.net/post/https://sunny.garden/users/dacmot/statuses/116370170808485464</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sunny.garden/users/dacmot/statuses/116370170808485464</guid><dc:creator><![CDATA[dacmot@sunny.garden]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:04:49 GMT</pubDate></item><item><title><![CDATA[Reply to In an E2EE system, how does Alice know what Bob&#x27;s public key is? on Wed, 08 Apr 2026 16:54:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/dacmot%40sunny.garden">@<span>dacmot</span></a></span> how does Alice know that's Bob's actual public key and not Mallory's?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/ghosttie/statuses/116370130856402817</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/ghosttie/statuses/116370130856402817</guid><dc:creator><![CDATA[ghosttie@mastodon.gamedev.place]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:54:39 GMT</pubDate></item><item><title><![CDATA[Reply to In an E2EE system, how does Alice know what Bob&#x27;s public key is? on Wed, 08 Apr 2026 16:53:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghosttie%40mastodon.gamedev.place">@<span>ghosttie</span></a></span> it's public, so either Bob can send it to Alice, or if it's part of a system like Signal, then the public key is part (maybe hidden /abstracted) of the user profile data.</p>]]></description><link>https://board.circlewithadot.net/post/https://sunny.garden/users/dacmot/statuses/116370125965535884</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sunny.garden/users/dacmot/statuses/116370125965535884</guid><dc:creator><![CDATA[dacmot@sunny.garden]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:53:25 GMT</pubDate></item></channel></rss>