If you use netcat you also do not use tls, try openssl s_client -connect server:port instead.
If you use netcat you also do not use tls, try openssl s_client -connect server:port instead.
if it's public: who cares, and if it isn't: why are people trusting random IRC server admins
especially when there have previously been leaks from places like EFNet where admins have been caught running tcpdump or ircsniff.pl
e2ee means that you do not have to trust anyone
> if it's public: who cares
IRC also lacks end to end authentication, the server owner can pretend to be you.
Fortunately, there's OTR, but client support is limited.
I wish the new ircstandarization efforts did work something out about e2e, at least for private messages.
On IRC, IRC over TLS doesn't have the same threat model as E2EE. With IRC over TLS, the server(s) can read the data plaintext. With proper E2EE (not the marketing version) that's not the case; only clients can read the data. I'm talking about actual data/content here; not metadata.
Yep, and all they'd see is encrypted garbage, unless they have encryption keys, if the messages are end-to-end encrypted. That's the whole point.
There are ways to do this on IRC (e.g. libfish), but no idea how that crypto actually stacks up by todays standards.
Yep, and they would have the encryption keys, for most channels, if the channels are to remain public, no?