4 ms·
It's hidden, but is it encrypted?
by drKarl 4y ago
It's hidden, but is it encrypted?
- bawolff 4y agoAll hidden services encrypt the connection (its part of the tor protocol), so yes.
- jazzyjackson 4y agoIn case the parent meant "end to end" encrypted, no, of course the IRC server can see all the messages, but if you're the one setting up the chatroom for you and your friends, it's a bit of a moot point, the chat will be encrypted and anonymous as far as anyone outside the chat is concerned.
- hkt 4y agoVarious IRC clients have OTR plugins though, for the truly paranoid: https://irssi.org/documentation/help/otr/ https://irssi.org/documentation/help/otr/ https://github.com/onezero1/xchat-otr https://github.com/onezero1/xchat-otr There's more listed here from the people who built and designed the libraries: https://otr.cypherpunks.ca/software.php https://otr.cypherpunks.ca/software.php NB, OTR is old and I can't vouch for its crypto, do your research if for some reason you're connecting to an irc server with a hostile admin where you absolutely have to exchange compromising information. (Duh)
- upofadown 4y agoOTR is inherently 1 on 1. Any idea how you can make it work for group discussions?
- blueflow 4y agoNobody on IRC uses OTR, people just talk unencrypted, trusting the server. It isn't that bad tho when its your friends IRC server.
- Eupraxias 4y agoExactly. People should use IRC as a tool for communications that don't really need encryption. If you are someone's high-value target, don't use IRC.
- bawolff 4y agoI think the point is more - there is no point end to end encrypting if the middle man (the irc server) is also part of the conversation (your friend). encryption cannot protect you from the person you are talking to only from the people trying to evesdrop.
- hkt 4y agoI've used it to talk to people in the past. It is uncommon but not unheard of.
- sedatk 4y agoI don't know why you were downvoted, I had the same question. Port 6667 means to me that it's plaintext, but it looks like hidden services don't have the "exit node leak" problem clients have with plaintext protocols because they're not involved in the traffic with the hidden services. It looks like the traffic's encrypted all the way.