Talk:Off-the-Record Messaging protocol
Add topic| This is the talk page for discussing improvements to the Off-the-Record Messaging protocol article. This is not a forum for general discussion of the subject of the article. |
Article policies
|
| Find sources: Google (books · news · scholar · free images · WP refs) · FENS · JSTOR · TWL |
| Archives: 1Auto-archiving period: 3 months |
| This article is rated Start-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | ||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||
IM Plus supports OTR
[edit]IM Plus supports OTR, mentioned eg. here:
https://otr.cypherpunks.ca/software.php
Android (free):
https://play.google.com/store/apps/details?id=de.shapeservices.impluslite
Android paid:
https://play.google.com/store/apps/details?id=de.shapeservices.implusfull
iOS:
http://www.shape.ag/en/products/details.php?product=im&platform=iphone
I have tried the Android version. Cannot comment on other platforms at the moment.
IM Plus appears to be completely ignored in all instant messaging articles here for some reason.
Weaknesses
[edit]Maybe this is an offtopic subject and this should be placed somewhere else, but I assume that people writing and discussing OTR are experts, so they could awnser my question
If the security and safety of a application is as strong as the weakest part in chain of creation and use. Are then not the application, its creator and its protocol the weakest part, but the OS the application is running on? A simple and undetected keylogger running on OS level could already expose all the input of users?
If a Microsoft or Google allow for 3rd parties or themselves an undetectable keylogger running on their OS, then all security of an app is breached? Also when 3rd parties do find exploits without OS creators knowing of it.
Correct me if i'm wrong. I have just the idea that nobody is really safe on the web if you are using any app running on an OS that "helps" breaching its security. — Preceding unsigned comment added by 2001:464A:91BD:0:184B:3853:EE3D:95E6 (talk) 18:15, 11 November 2018 (UTC)
key exchange vulnerability
[edit]Does the section https://en.wikipedia.org/wiki/Off-the-Record_Messaging#Authentication mean the man-in-the-middle security flaw described at https://xmpp.org/extensions/xep-0364.html#security is fixed in OTR 3.1? Otherwise we could add this from the link above in the article: "Because Diffie-Hellman (D-H) key exchange is unauthenticated, the initial D-H exchange which sets up the encrypted channel is vulnerable to a man-in-the-middle attack." --Baptx (talk) 12:43, 28 October 2021 (UTC)
- To quote from the link you provided: "No sensitive information should be sent over the encrypted channel until mutual authentication has been performed inside the encrypted channel." So there isn't a "security flaw" to "fix", it's just stating that the initial handshake and authentication are done separately, and implementations need to be aware they should do that. But yes, the normal way authentication is done in OTR is SMP, as described in the section you linked. --Tga (talk) 18:24, 28 October 2021 (UTC)
Requested move 1 October 2023
[edit]- The following is a closed discussion of a requested move. Please do not modify it. Subsequent comments should be made in a new section on the talk page. Editors desiring to contest the closing decision should consider a move review after discussing it on the closer's talk page. No further edits should be made to this discussion.
The result of the move request was: Page moved. (closed by non-admin page mover) Jerium (talk) 19:39, 8 October 2023 (UTC)
Off-the-Record Messaging → Off-the-record messaging – Per MOS:EXPABBR. This seems more of a technology than strictly a proper name to me at this point. Feel free to disagree. alexiaa (talk) 10:10, 1 October 2023 (UTC)
- Support. Agree with the nom that as currently written the article covers the topic as a technology. Jenks24 (talk) 09:43, 5 October 2023 (UTC)
- Start-Class Computing articles
- Unknown-importance Computing articles
- All Computing articles
- Start-Class law articles
- Unknown-importance law articles
- WikiProject Law articles
- Start-Class Cryptography articles
- Unknown-importance Cryptography articles
- Start-Class Computer science articles
- Unknown-importance Computer science articles
- WikiProject Computer science articles
- WikiProject Cryptography articles
