The more interesting would be to see how feasible is to crack the in band SAS authentication string, when callers verbally verify it. Deep learning and ability to train on a specific callers' voice [1] then mimic it might be an interesting attack vector. In practice Silent Circle's implementation does something interesting and instead of SAS numbers use dictionary words. So you end up with something like "Pink Elepha…
Author of the paper here. There is existing work on testing the feasibility of impersonating other person's voice. We discuss them in our related work section at the end of the paper. I think on the long run, SAS will no longer be a sufficient authentication technique due to advances in speech synthesis. To prolong ZRTP's life we propose usage of sentences instead of words/chars. This is discussed in detail in our be…
I noticed that UX/UI is important and a guarantee that SAS should increase in length, what are some of the recommendations that you advise to have a good ZRTP implementation ?
Or should we start discussing the fadeoff of ZRTP and a change to something like Matrix protocol or even Signal's one ?