3 ms·
OTR [1], Axolotl [2] and OMEMO [3] all provide Perfect Forward Secrecy, which in turn means that you can't (or should not be able to) read your archived message
by Flowdalic 11y ago
OTR [1], Axolotl [2] and OMEMO [3] all provide Perfect Forward Secrecy, which in turn means that you can't (or should not be able to) read your archived messages. And with OTR can't send messages to offline contacts. OpenPGP does not provide this property, which allows you to read your encrypted messages in the archive as long as you have access to your OpenPGP secret key and it allows you to send messages to offline contacts.
1: https://otr.cypherpunks.ca/ https://otr.cypherpunks.ca/
2: https://github.com/WhisperSystems/Signal-Android/wiki/ProtocolV2 https://github.com/WhisperSystems/Signal-Android/wiki/Protoc...
3: http://conversations.im/omemo/ http://conversations.im/omemo/
- mkj 11y agoIf you're archiving at all then OTR won't encrypt them - it's not going to archive the ciphertext. I guess offline contacts is a use case against OTR, though whisper's certainly has that sorted out already. https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/advanced-ratcheting/
- daturkel 11y agoYeah I've never seen an implementation of OTR that blocked archival—in the journalistic sense, it's still on the record so to speak. (That being said, OTR's deniable authentication means I can use my plaintext archive to recall the conversation but I can't prove to a third party that it's from who I say it was—nor would I be able to if I was storing the encrypted conversation.) With the above considered, I'm curious to hear another argument for OpenPGP over XMPP rather than OTR. (Edit: Should say that there likely are OTR implementations that archive the ciphertext, or don't automatically archive at all. However, having used OTR in Jitsi and Adium, both I believe keep regular old plaintext logs.)
- iheartmemcache 11y agoEven if it was blocked by the implementation, the second it hits your local machine is the second an end-user can capture it (either by recompiling the plugin, the base software, hooking DLLs, accessing the heap directly, with screenshots or even with a Polaroid). The only advantage of OpenPGP/GnuPG over XMPP I can think of is it supports multiple end-users via merged groups out of the box. With OTR it's harder to logistically organize multi-session key-sharing. And if one of your machines is compromised, you can do a PKI revoke via CRL (or whatever it's called in GPG, slipping my mind at the moment).
- anc84 11y agoOMEMO lists offline delivery as a key feature. I would have been shocked if it did not support it because that would be a "useless and dead in the water" blocker for new technology in our mobile world.
- Flowdalic 11y agoRight, shouldn't have thrown them all together. Corrected the comment.
- infinity0 11y agoThis is a bad security argument. With OTR / FS in general, you can re-encrypt the plaintext using a different local-only key after decrypting the forward-secure ciphertext. Then, the ciphertext that was sent over the wire is still forward-secure, and your adversary must seize your computer in order to try to decrypt the re-encrypted non-FS ciphertext you use for logs/archiving. There really is no reason to use non-FS encryption over FS encryption for ciphertext sent over the wire.
- ultramancool 11y agoYeah, what I always did was keep the logs on an encrypted file system... it's not like you're going to pcap your traffic to store your chat logs.