[OTR-dev] Secure connections through a connect/disconnect cycle, OTR error messages

Ian Goldberg ian at cypherpunks.ca
Thu Jan 27 12:35:03 EST 2005


On Thu, Jan 27, 2005 at 11:06:44AM -0600, Evan Schoenberg wrote:
> *nod* I meant that the notification would be sent in the OTR context 
> before the client disconnects, not in plaintext after it disconnects, 
> so it would not be possible for the "other side requested OTR 
> disconnect" message to be emulated by a third party.

So when you click "end private connection", the client first sends an IM
like "[ending private connection]" (as if you'd typed that string), and
then forgets the context?

That'd be fine, security-wise; it'd just be an automated form of what
people can do now.

   - Ian



More information about the OTR-dev mailing list