[OTR-dev] Separate Fingerprint For Each Account?

Donny Viszneki donny.viszneki at gmail.com
Sun Sep 21 18:04:14 EDT 2008


On Sat, Sep 20, 2008 at 3:07 PM, Ian Goldberg <ian at cypherpunks.ca> wrote:
> That's great, so long as your IM client has the concept of "all these
> account's I've seen are really the same person".  Then if it sees a new
> IM account using the same OTR key, it can automatically add that new
> account to the bunch.

I believe this is the primary point of confusion for otr at synx.us.to. I
believe he assumes that this is an inherent part of the OTR protocol,
because he believes that your OTR plugin has access to data during any
OTR conversation which it could compare with a list of OTR users it
has "talked to" in the past, thus allowing it to deduce if that person
is already known.

This also requires the assumption that an OTR key is not inherently
tied to a specific messenger account/username/address -OR- the
concession that the initiation of an OTR conversation requires the
disclosure of some sort of unique identifier by which you can be
identified.

One or both of these may be true, I don't know which, I hope someone
who knows will tell us.

-- 
http://codebad.com/



More information about the OTR-dev mailing list