in reply to sharing secret without ssl
True, I just realized I can simply use Diffie-Hellman or the like.
I consider this question solved.