[Linuxdcpp-team] [Bug 1445330] Re: CCPM and hub connection encryption

2015-04-17 Thread maksis
Ah, but isn't KEYP meant to prevent connection hijacking, so even that doesn't seem possible. -- You received this bug notification because you are a member of Dcplusplus-team, which is subscribed to DC++. https://bugs.launchpad.net/bugs/1445330 Title: CCPM and hub connection encryption Statu

[Linuxdcpp-team] [Bug 1445330] Re: CCPM and hub connection encryption

2015-04-17 Thread maksis
I understand requiring the CCPM connection to be encrypted but not why the _hub_ connection needs to be encrypted. Because someone could snoop the token that is sent through the hub and hijack the connection? The same applies to encrypted transfer connections as well, but they can still be establi

[Linuxdcpp-team] [Bug 1445330] Re: CCPM and hub connection encryption

2015-04-17 Thread poy
when we tell the user her connection is encrypted, she expects no one will be able to snoop on it, be it the hub or a third-party. i fear the CCPM + unencrypted connection combo may lead users to think they are safe, when in reality they aren't. the specifics of such a situation would also be quite