Comment by egwor
4 hours ago
I've built the same code but in swift. I've come to the exact same conclusions that you have on the protocol. I got Claude Code to implement TPAP compatibility solely by interacting with my local plugs, looking at the shape of responses and RFC 9383 to figure out it was SPAKE2+. It took a bit of time to figure out the last bit: that the SHA-1 of the password, then PBKDF2 with the plug's salt, split into two halves; a context of "PAKE V1" plus both sides' random numbers; empty identities
No comments yet
Contribute on Hacker News ↗