Re: Manifest without end-to-end encryption?
Waqas Hussain <[email protected]> Wed, 1 Jan 2014 22:52:39 -0500
| Newsgroups | gmane.network.jabber.user |
|---|---|
| Message-ID | <CALm9TZ9m=fbtyA-pCsLaRfgTG7GkLWi9KQqQywCiDgJ7uBUZ7g@mail.gmail.com> |
On Tue, Dec 31, 2013 at 6:39 AM, Randolph <[email protected]> wrote: > Why is the manifest > https://github.com/stpeter/manifesto/blob/master/manifesto.txt > not adding end-to-end encryption? > The manifesto is focused on short-term quickly achievable goals. From the manifesto itself: > This commitment to encrypted connections is only the first step > toward more secure communication using XMPP, and does not obviate > the need for technologies supporting end-to-end encryption (such as > Off-the-Record Messaging or OTR), strong authentication, channel > binding, secure DNS, server identity checking, and secure service > delegation. Although we have worked to implement and deploy such > technologies and will continue to do so, we believe that encrypting > the traffic on the XMPP network is a necessary precondition to > offering further security improvements. So, end-to-end encryption is something we certainly want, along with a bunch of other things, but it just isn't going to get done in the next 3-4 months (e2e can get pretty complex, and spec work is still ongoing). -- Waqas Hussain _______________________________________________ This is JUser -- a mailing list for end users of Jabber/XMPP clients. To unsubscribe, send email to [email protected] or go to the following web page, scroll all the way down, and type in your email address: http://mail.jabber.org/mailman/listinfo/juser _______________________________________________