Steganographic key transfer in fake encrypted e-mails

This is a real situation. Deltachat QR codes and invite links are easily recognized, and blocked, cheaply; this seems to be happening.

Threat model: authoritarian government with substantial control over communications, including ability to intercept and modify, but with limited resources, and unwilling to block all encrypted mail.

A shared secret is useless if your comms are blocked. I assume the secret is not prearranged but preexisting, and may not have any specific trait, like length.

So I asked “What is an easy way to transmit a key between DC clients in a form that won’t get blocked?”

1 Like