[OTR-dev] Protocol Clarification

Ian Goldberg ian at cypherpunks.ca
Fri Jan 27 20:31:21 EST 2006


On Fri, Jan 27, 2006 at 05:09:45PM -0800, Andrew S. Morrison wrote:
> In the "OTR Messaging Protocol Version 2" docs, the first transmission is
> stated to contain {g^x, HASH(g^x}. In the slides for WPES, it is stated to
> be {g^x, SIGN_A(g^x} and in the paper for WPES it is stated to be
> {g^{x_1}}. Where may I find the canonical protocol specification?

WPES was OTR protocol version 1.  "Off-the-Record Messaging Protocol
version 2" is the current spec, where it (correctly) says that the first
message is { AES_r(g^x), HASH(g^x) }.

   - Ian



More information about the OTR-dev mailing list