Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Steve Van Doorn
Thanks. Looks like an interesting project. Not just end-to-end security with OTR, but uses Tor for anonymity. OTR itself is an interesting project:

Encryption: No one else can read your instant messages.

Authentication: You are assured the correspondent is who you think it is.

Deniability: The messages you send do not have digital signatures that are checkable by a third party. Anyone can forge messages after a conversation to make them look like they came from you. However, during a conversation, your correspondent is assured the messages he sees are authentic and unmodified.

Perfect forward secrecy: If you lose control of your private keys, no previous conversation is compromised.

The deniability is the most interesting. Normally PKI is semi-permanent and everyone knows you by your signature, made with the private key that only you control. But here it looks like disposable private keys: https://otr.cypherpunks.ca/Protocol-v3-4.1.1.html My question is how does Alice know who Bob is? It seems as though they first need a traditional PKI solution to authenticate, then they can use this to send messages. Of course the traditional solution could use a yubikey (hardware private key) handed off in person.

12 posted on 04/14/2019 4:52:33 AM PDT by palmer (...if we do not have strong families and strong values, then we will be weak and we will not survive)
[ Post Reply | Private Reply | To 8 | View Replies ]


To: palmer

Thank you for that review.


15 posted on 04/14/2019 4:52:29 PM PDT by Steve Van Doorn (*in my best Eric Cartman voice* 'I love you, guys')
[ Post Reply | Private Reply | To 12 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson