Off-the-Record Messaging – encrypt your instant messages
cypherpunks.ca
cypherpunks.ca
1. https://github.com/chrisballinger/Off-the-Record-iOS
I have an android phone with gibberbot, so its an academic question, but that very scenario has been a pain for me.
Do you think the up coming work on multi party OTR helps solve this problem?
mpOTR [2][3] is designed to solve a different problem, and I believe development has been stalled because the current design doesn't allow chatrooms to scale to large numbers of people.
1. http://www.cypherpunks.ca/otr/Protocol-v3-4.0.0.html
If you really want super paranoid level security, communicating digitally is probably not your best bet anyway.
Here's the SHA1 checksum of the compiled binary from the latest release (2.0):
f9347ae51c3276f4b34fba0be7c0648f20c8c11e /Applications/ChatSecure.app/ChatSecure
Considering the fact that Apple is in the NSA wiretapping program and involved in secret tracking [1], don't you think it's unfair to call someone who's asking a way to verify if Apple isn't messing with the code "super paranoid"?
That's why it's better to use Crypto.Cat - its source is the executable. Verifying the hash is enough to make sure the source code didn't change.
You've gotta draw the line somewhere (unless you're rms). I would venture to say an open source OS and applications on worldwide-deployed hardware in the hundreds of millions count is probably safe enough for my purposes.
The amount of money we could make by selling the app directly to users wouldn't even begin to support the actual cost of producing and supporting the software.
I still don't trust it, as the binaries come via the App Store (and without paying another $100 I can't build/install them myself), but it's good that someone's taken the first steps.
For example, if your adversary is some big national agency, you are chatting this way, but both of you don't anonymize yourselves properly, you could just raise suspicion [since most people don't chat encrypted] and more surveillance can be deployed against you.
To sum it up, the technology is good, but if it should be used for more than an exercise, it must be combined with other protection.
"Hiding anomalous activity is hard, but vitally important. The problem with many security systems based purely on secrecy is that their usage is itself anomalous. It singles out and attracts attention to the users. If the adversary doesn’t know who those users are initially, they can cross correlate real world data with the suspicious activity and narrow their focus to real people."
* Assuming you believe no one has the resources to impersonate your chat partner in near real time.
I like gpg based chats better for that reason, people tend to keep the same key.. it works more or less everywhere (except phones somehow) AND.. if you trust their keys you don't have anything to do it just works, regardless of being IM, email, or whatever else. One trust db. Not 100.
I would like to see an automatic way to use GPG to sign OTR keys, though. You can create a message "My OTR fingerprint is abcdef..." and sign that, but it would be nice if clients did that automatically. Or maybe even use the GPG key itself instead of the OTR key...
EDIT: I just remembered, my HN profile also contains my OTR fingerprint, and is signed using my PGP key.
Some bugs in the old 0.3 release are quite annoying.
He ended up having to block me on AIM because my adium instance at home went into a resend-frenzy while I wasn't even at home...