[OTR-users] How does deniability work?

Thomas Henlich Thomas.Henlich at tu-dresden.de
Tue Apr 25 12:04:37 EDT 2006


I have read the CodeCon presentation and still don't fully understand
how deniability works:

"Anyone can forge messages after a conversation to make them look like
they came from you. However, during a conversation, your correspondent
is assured the messages he sees are authentic and unmodified."

If at some point in the conversation (after each message?) the old
message key is published, doesn't it open up the possibility for a MITM
attack? I.e. the attacker intercepts and holds back two of Alice's
messages and uses the message key from the second message to forge a
message and sends it to Bob?

Any pointers to more information are appreciated.

-- 
Thomas



More information about the OTR-users mailing list