[OTR-dev] private messages on dbus

Dimitris Glynos dimitris at census-labs.com
Tue Dec 20 05:02:38 EST 2011


Hello all,

I was wondering if pidgin could allow for certain chat types
to be flagged as private and not transmit these over dbus.
I don't know how much dbus is hardwired to pidgin (is it used
also for capturing the messages displayed on the pidgin GUI?)
but the fact that a local attacker can access OTR plaintext
from a dbus session monitor is quite unnerving.

I'm CC-ing this to otr-dev as well in the hope that an elegant
solution might spring up from the discussion.

Cheers,

Dimitris



More information about the OTR-dev mailing list