That's why I suggest, in another thread, that the keys be exchanged via a secure back-channel, such as email signed with verified pgp/gpg keys. I agree that the automatic key exchange is dangerous, but it's a nice convenience as long as you ALWAYS verify the keys via a secure channel.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Any encryption where the key needs to be sent in a similar method to the message is insecure.
That's why I suggest, in another thread, that the keys be exchanged via a secure back-channel, such as email signed with verified pgp/gpg keys. I agree that the automatic key exchange is dangerous, but it's a nice convenience as long as you ALWAYS verify the keys via a secure channel.