[OTR-users] New gaim-otr and otrproxy ready for beta testing

Ian Goldberg ian at cypherpunks.ca
Sun Oct 16 17:14:21 EDT 2005


After what seems like forever, the new gaim-otr and otrproxy are ready
for beta testing.  Please report problems you encounter, particularly
when you and/or your buddy is logged in multiple times; we don't have a
good handle on how that should be resolved just yet.

The primary change in this version is the implementation of OTR Protocol
version 2, using the SIGMA AKE (Authenticated Key Exchange).  This
resolves the identity-binding flaw that was pointed out in version 1.
This version will fall back to version 1 if your buddy can't speak
version 2, but it will warn you it's doing so.

Other changes include:

gaim-otr:
    - Almost all of the popups have been changed to inline messages.
    - New fingerprints don't block everything until you verify them;
      rather, you are merely informed of the new fingerprint, and
      conversations using it will be marked "Unverified" until you
      indicate that you've verified it (at which point the
      conversations will be marked "Private").
    - The OTR button now has icons in addition to text (and they
      properly obey gaim's "text and/or icons" setting), as well as a
      right-button context menu containing some useful options.

otrproxy:
    - Handle non-ASCII charsets properly.

Not implemented yet:
    - Being able to configure whether to fall back to version 1 or not.

You can check out the new code from sourceforge CVS:

http://sourceforge.net/cvs/?group_id=128860

We've also built some Windows binaries.  NOTE: there are not installers;
they're meant to replace the corresponding files in older versions.  So
if you've already got an older version of gaim-otr installed, just
replace the gaim-otr.dll file with the one in the gaim-otr zip file.
Similarly, replace the otrproxy.exe file you've got with the one in the
otrproxy zip file.  If you don't have OTR software installed yet, either
install the last release, and continue as above, or just sit tight and
wait for a release.  ;-)

http://otr.cypherpunks.ca/binaries/windows/gaim-otr-3.0.0beta1-win32.zip
http://otr.cypherpunks.ca/binaries/windows/otrproxy-0.3.1beta1-win32.zip

If someone wants to compile up binaries for OSX, that'd be awesome.
I'm assuming Unixy people will just compile their own; if that's a bad
assumption, we can try to put up some binaries for them as well.  But
you may just want to wait for the release, when the various package
maintainers will have their way with it.  ;-)

Remember: these are *betas*.  Which means we're pretty sure they work,
but we want feedback.  Send feedback to this list, or by email to
<otr at cypherpunks.ca>.

Note to Evan: it look less than an hour to convert gaim-otr to use the
new API.  I assume doing the same for the Adium X native-UI stuff will be
similar, but let us know if you run into problems.

Note to package maintainers: please don't package the betas; we hope to
release this version in short order.  [And when we *do* release it,
remember that it's a security fix, for package formats that can
accomodate such notations.]

Thanks, and have at it!

   - Ian



More information about the OTR-users mailing list