Comment (by infinity0):

 In authenticated transfers (that resist active attacks) such as
 scramblesuit, each bridge has its own shared secret. A fog client running
 scramblesuit|websocket needs to know the shared-secret for the bridge that
 it connects to.

 One way of doing this, is to solve this bug, then let the client express
 the shared-secret on the Bridge line. This would be consistent with other

 Another way of doing this, is to let the facilitator (somehow) communicate
 the shared-secret back to the client. This would involve additional
 complexity in the proxy-client protocol, but also on the fog client side,
 since flashproxy would (somehow) need to pass this shared-secret back to

 I believe this bug is a cleaner solution than the latter, but I haven't
 thought of all possible solutions, so there may be a better one.

