Thanks to @matthew and Hubert Chathi for their kind, supplementary comments on my latest blog post about Olm/Megolm encryption.
https://blog.jabberhead.tk/2019/03/10/a-look-at-matrix-orgs-olm-megolm-encryption-protocol/
Thanks to @matthew and Hubert Chathi for their kind, supplementary comments on my latest blog post about Olm/Megolm encryption.
https://blog.jabberhead.tk/2019/03/10/a-look-at-matrix-orgs-olm-megolm-encryption-protocol/
#OMEMO is a big fish 🐠 in the upcoming #Debian 10 release (#buster) bowl. It hopefully will feature five #XMPP clients with this modern #e2e #encryption: #Gajim, #Dino, #Psi+ (all graphical), #jp (command line), and #primitivus (console), the latter two part of #SalutAToi or #SaT
OMEMO encryption update just pushed in SàT, it's now fully implemented for one2one chat (will probably do group encryption for next release), fingerprint management included (no QR Code yet). As always, it's also available from command line, sending an encrypted message is as simple as `echo something | jp message send -e omemo somebody@example.net`.
OTR still working too, with same mechanism.
Me acabo de acordar haber leido en alguno de los servidores de
https://gist.github.com/dllud/a46d4a555e31dfeff6ad41dcf20729ac
que aunque ellos cuidan de no guardar casi nada, aun asi, ellos alertan de que muchos servidores guardan metadatos: hora de (des)conexion, cliente, version, e incluso las conversaciones.
Es por eso mismo que debemos SIEMPRE usar #OTR / #OMEMO / #GPG
¿Sabias que incluso se puede usar directamente #GnuPG para cifrar las conversaciones?
Y seria muy bueno usar siempre 🔒 servidores compatibles con #Tor
@infosechandbook Well, #OMEMO is a #XMPP XEP, so I don't understand "it isn't a standard". If #MLS comes true, I hope it becomes at least clearly defined in the XMPP standardization track and it would also be a plus if it became mandatory.
source: https://gultsch.de/omemo_by_default.html
Moxie #Marlinspike, in his 2016 propaganda piece ignorantly bashing #XMPP, had one valid point: Enabling end-to-end encryption in a homogenous environment is easier than introducing it in a heterogenous one like #Jabber. Nobody is denying that. However, if something is hard to achieve there are two possible approaches: Either try your best and don’t give up, or put your head in the sand and create yet another walled garden that is no different from other proprietary solutions.
Admittedly it has taken us a while to get to a point where we can enable end-to-end #encryption by default, but it was worth the effort in that we ended up with something that is different from #WhatsApp in more than just marketing.
PS: You can find cool xmpp servers here: https://anonsurvivalguide.wordpress.com/2017/03/13/xmpp-jabber-server-list/
#chat #communication #internet #OpenSource #Software #News #decentaralization
The rocky road to OMEMO by default - https://gultsch.de/omemo_by_default.html
Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.
All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.