[OTR-dev] Flaw in OTR Protocol (with workaround!)

Ian Goldberg ian at cypherpunks.ca
Thu Aug 4 09:09:05 EDT 2005


On Thu, Aug 04, 2005 at 08:19:02AM -0400, Greg Troxel wrote:
> Also, I should say thanks for all your work on OTR - I use it daily.
> 
> I just changed the per-user policy for one correspondent and on typing
> a message got the policy violation popup.  Then I got an 'established'
> popup (I had previously accepted public key fingerprint).  I'd prefer
> to see these inline, as I don't consider them error cases.  At least
> I'd like the first popup to be changed to show the exchange complete,
> rather than leaving two.

Most popups are now inline in the CVS version.

> This is exactly the behavior (modulo popup/inline issues) I'd like to
> see for Private/Broken.  Essentially Private/Broken would force
> "require OTR" policy.

What is different about what you want vs. the current "end private
conversation" functionality?

   - Ian



More information about the OTR-dev mailing list