<?xml version="1.0" encoding="UTF-8" ?>
<rdf:RDF
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://blog.bepointbe.be/index.php/">
  <title>Gof's weblog - Commentaires</title>
  <description><![CDATA[Blog de Olivier Goffart]]></description>
  <link>http://blog.bepointbe.be/index.php/</link>
  <dc:language>fr</dc:language>
  <dc:creator></dc:creator>
  <dc:rights></dc:rights>
  <dc:date>2007-04-02T13:23:25+02:00</dc:date>
  <admin:generatorAgent rdf:resource="http://www.dotclear.net/" />
  
  <sy:updatePeriod>daily</sy:updatePeriod>
  <sy:updateFrequency>1</sy:updateFrequency>
  <sy:updateBase>2007-04-02T13:23:25+02:00</sy:updateBase>
  
  <items>
  <rdf:Seq>
    <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c388" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c387" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c386" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c385" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c384" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c383" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c382" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c381" />
  <rdf:li rdf:resource="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c380" />
  </rdf:Seq>
  </items>
</channel>

<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c388">
  <title>trackback - mod_otr: Man in the midle for OTR (module for ejabberd) - anothr user</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c388</link>
  <dc:date>2007-04-02T13:23:25+02:00</dc:date>
  <dc:creator>anothr user</dc:creator>
  <description>Anothr feed track -Planet JabberFR
One new subscriber from Anothr Alerts:...</description>
  <content:encoded><![CDATA[<!-- TB -->
<p><strong>Anothr feed track -Planet JabberFR</strong></p>
<p>One new subscriber from Anothr Alerts:</p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c387">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - berkus</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c387</link>
  <dc:date>2007-04-01T14:39:26+02:00</dc:date>
  <dc:creator>berkus</dc:creator>
  <description>OTR is called so for a reason - Off the record means "Do not record anything".

Why would you ever need to store these messages?...</description>
  <content:encoded><![CDATA[<p>OTR is called so for a reason - Off the record means &quot;Do not record anything&quot;.<br />
<br />
Why would you ever need to store these messages?</p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c386">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - Thomas Zander</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c386</link>
  <dc:date>2007-03-30T19:34:44+02:00</dc:date>
  <dc:creator>Thomas Zander</dc:creator>
  <description>Gof wrote;
  "PGP encryption doesn't suffer from this problem, but PGP encryption is not user friendly (you need to create your private key, and share it)"

Very true. One thing that would go a long way to making this more user friendly is to increase support in apps like kopete (and...</description>
  <content:encoded><![CDATA[<p>Gof wrote;<br />
  &quot;PGP encryption doesn't suffer from this problem, but PGP encryption is not user friendly (you need to create your private key, and share it)&quot;<br />
<br />
Very true. One thing that would go a long way to making this more user friendly is to increase support in apps like kopete (and KMail etc).  Things like having a remote client ask for the public key and then sending it automatically is one thing. This, naturally, should happen without user interaction.<br />
The only hard part left, then, is to ask the user to do the real checking that the key belongs to the remote user.  Without it you can locally sign, or just not sign, and send the messages encrypted.<br />
<br />
But the basic personal identity v.s. the server identity that gpg imposes already goes a long way in ensuring better security.<br />
<br />
In short; I'm convinced if we automate a lot of the hard part of gpg we can let a larger group of people enjoy its features.</p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c385">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - ian paterson</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c385</link>
  <dc:date>2007-03-30T15:21:25+02:00</dc:date>
  <dc:creator>ian paterson</dc:creator>
  <description>Hi Olivier,

First of all, congratulations! I think it is really really cool that you implemented this module and made it available. It will help raise consciousness regarding security issues. Thank you.

Regarding your doubts about the value of e2e... Do you check the fingerprint whenever you...</description>
  <content:encoded><![CDATA[<p>Hi Olivier,<br />
<br />
First of all, congratulations! I think it is really really cool that you implemented this module and made it available. It will help raise consciousness regarding security issues. Thank you.<br />
<br />
Regarding your doubts about the value of e2e... Do you check the fingerprint whenever you use SSH for the first time with a server? Assuming you don't (since most people don't), do you believe SSH offers you more security than telnet? Do you assign any value to that security? Assuming you do, why is e2e different?<br />
<br />
Security is not free. Even with e2e it is perfectly possible to archive messages on your server in a way that is 100% transparent to the user. Your client could even send the e2e decryption keys to your server to allow it to archive automatically (that way you are still protected against a compromise of your contact's server). Alternatively your client can push the decrypted messages back to the server (probably re-encrypted using xmlenc). Security is not free.<br />
<br />
BTW, assuming OTR caches contact's public keys, your MITM module will have to be present from the very first communication between the two clients (just as with SSH).<br />
<br />
&quot;All the proposals of an easy to use e2e encryption suffer from the same problem.&quot;<br />
<br />
ESessions employs Short Authentication String (SAS). This is an authentication technique which (although it is still not transparent) is a much more human friendly method than public key fingerprint comparison.</p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c384">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - steve</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c384</link>
  <dc:date>2007-03-30T14:25:42+02:00</dc:date>
  <dc:creator>steve</dc:creator>
  <description>You can digg this: digg.com/security/Man_in_......</description>
  <content:encoded><![CDATA[<p>You can digg this: <a href="http://digg.com/security/Man_in_the_middle_attack_for_Off_the_Record_Messaging_OTR" title="http://digg.com/security/Man_in_the_middle_attack_for_Off_the_Record_Messaging_OTR" rel="nofollow">digg.com/security/Man_in_...</a></p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c383">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - Nÿco</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c383</link>
  <dc:date>2007-03-30T09:38:59+02:00</dc:date>
  <dc:creator>Nÿco</dc:creator>
  <description>The OpenPGP usage in IMP is not that good:
www.xmpp.org/extensions/x......</description>
  <content:encoded><![CDATA[<p>The OpenPGP usage in IMP is not that good:<br />
<a href="http://www.xmpp.org/extensions/xep-0027.html" title="http://www.xmpp.org/extensions/xep-0027.html" rel="nofollow">www.xmpp.org/extensions/x...</a></p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c382">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - Gof</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c382</link>
  <dc:date>2007-03-30T09:28:56+02:00</dc:date>
  <dc:creator>Gof</dc:creator>
  <description>You can't store OTR messages, because a key session is used, and the key session is not stored


PGP encryption doesn't suffer from this problem, but PGP encryption is not user friendly (you need to create your private key, and share it)...</description>
  <content:encoded><![CDATA[<p>You can't store OTR messages, because a key session is used, and the key session is not stored<br />
<br />
<br />
PGP encryption doesn't suffer from this problem, but PGP encryption is not user friendly (you need to create your private key, and share it) </p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c381">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - Thomas Zander</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c381</link>
  <dc:date>2007-03-30T09:06:52+02:00</dc:date>
  <dc:creator>Thomas Zander</dc:creator>
  <description>Doesn't kopete already support gpg encryption? Thats the best e2e kind of encryption possible (since its based on a personal identity, not a server identity) and you can store things on the server without problems. Storing on server works since you just use your own private key to decrypt stuff...</description>
  <content:encoded><![CDATA[<p>Doesn't kopete already support gpg encryption? Thats the best e2e kind of encryption possible (since its based on a personal identity, not a server identity) and you can store things on the server without problems. Storing on server works since you just use your own private key to decrypt stuff locally.<br />
<br />
Wondering.</p>]]></content:encoded>
</item>
<item rdf:about="http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c380">
  <title>mod_otr: Man in the midle for OTR (module for ejabberd) - ole</title>
  <link>http://blog.bepointbe.be/index.php/2007/03/29/20-mod_otr#c380</link>
  <dc:date>2007-03-29T19:00:51+02:00</dc:date>
  <dc:creator>ole</dc:creator>
  <description>you can store the history on the server encrpyted , and if the user wants to see the messages he has the key....</description>
  <content:encoded><![CDATA[<p>you can store the history on the server encrpyted , and if the user wants to see the messages he has the key.</p>]]></content:encoded>
</item>

</rdf:RDF>
