Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a258e3767bf3ada9

Jump to content

Talk:Off-the-Record Messaging protocol

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 2 years ago by Jerium in topic Requested move 1 October 2023

IM Plus supports OTR

[edit]

IM Plus supports OTR, mentioned eg. here:
https://otr.cypherpunks.ca/software.php
Android (free): https://play.google.com/store/apps/details?id=de.shapeservices.impluslite Android paid: https://play.google.com/store/apps/details?id=de.shapeservices.implusfull iOS: http://www.shape.ag/en/products/details.php?product=im&platform=iphone

I have tried the Android version. Cannot comment on other platforms at the moment.

IM Plus appears to be completely ignored in all instant messaging articles here for some reason.

Weaknesses

[edit]

Maybe this is an offtopic subject and this should be placed somewhere else, but I assume that people writing and discussing OTR are experts, so they could awnser my question

If the security and safety of a application is as strong as the weakest part in chain of creation and use. Are then not the application, its creator and its protocol the weakest part, but the OS the application is running on? A simple and undetected keylogger running on OS level could already expose all the input of users?

If a Microsoft or Google allow for 3rd parties or themselves an undetectable keylogger running on their OS, then all security of an app is breached? Also when 3rd parties do find exploits without OS creators knowing of it.

Correct me if i'm wrong. I have just the idea that nobody is really safe on the web if you are using any app running on an OS that "helps" breaching its security.  Preceding unsigned comment added by 2001:464A:91BD:0:184B:3853:EE3D:95E6 (talk) 18:15, 11 November 2018 (UTC)Reply

key exchange vulnerability

[edit]

Does the section https://en.wikipedia.org/wiki/Off-the-Record_Messaging#Authentication mean the man-in-the-middle security flaw described at https://xmpp.org/extensions/xep-0364.html#security is fixed in OTR 3.1? Otherwise we could add this from the link above in the article: "Because Diffie-Hellman (D-H) key exchange is unauthenticated, the initial D-H exchange which sets up the encrypted channel is vulnerable to a man-in-the-middle attack." --Baptx (talk) 12:43, 28 October 2021 (UTC)Reply

To quote from the link you provided: "No sensitive information should be sent over the encrypted channel until mutual authentication has been performed inside the encrypted channel." So there isn't a "security flaw" to "fix", it's just stating that the initial handshake and authentication are done separately, and implementations need to be aware they should do that. But yes, the normal way authentication is done in OTR is SMP, as described in the section you linked. --Tga (talk) 18:24, 28 October 2021 (UTC)Reply

Requested move 1 October 2023

[edit]
The following is a closed discussion of a requested move. Please do not modify it. Subsequent comments should be made in a new section on the talk page. Editors desiring to contest the closing decision should consider a move review after discussing it on the closer's talk page. No further edits should be made to this discussion.

The result of the move request was: Page moved. (closed by non-admin page mover) Jerium (talk) 19:39, 8 October 2023 (UTC)Reply


Off-the-Record MessagingOff-the-record messaging – Per MOS:EXPABBR. This seems more of a technology than strictly a proper name to me at this point. Feel free to disagree. alexiaa (talk) 10:10, 1 October 2023 (UTC)Reply

The discussion above is closed. Please do not modify it. Subsequent comments should be made on the appropriate discussion page. No further edits should be made to this discussion.