[OTR-users] Gaim plugin and archiving

Paul Wouters paul at cypherpunks.ca
Sat May 6 13:28:28 EDT 2006


On Fri, 5 May 2006, Ian Goldberg wrote:

> > If an unsuspecting user uses the plugin and has the logging option
> > activated,
> > the private OTR conversations will be archived as well in clear text,
> > breaking forward secrecy.
>
> It technically doesn't, because the logs are unauthenticated.  But I
> agree that the option to disable logging of OTR conversations is a fine
> plan, and it's already on the todo list (and I'm pretty sure the request
> is already on sourceforge).

People want want to keep logging, especially if they are using disk encryption
for their homedir (eg FileVault or something else). So please don't change
logging without telling the user. eg Make it an explicit option in the OTR
menu or something?

Paul



More information about the OTR-users mailing list