[OTR-users] Private Keys File

Richard M. Conlan offtherecord at embracetherandom.com
Thu Nov 16 00:46:37 EST 2006


For the GAIM plug-in, what is done to protect the otr.private_key file 
located at C:\Documents and Settings\<username>\Application Data\.gaim? 
Is it just protected by the Windows file system?

Since there is no password on startup I assume it is sitting there in 
the clear? Does this would imply that it is not protected from 
Administrators? This would mean that it isn't safe to use OTR at work, 
insofar as anybody with privileged access could get the key and do mitm 
with each.

I assume I am missing something?

=/

~RMC



More information about the OTR-users mailing list