Re: Manifest without end-to-end encryption?

Waqas Hussain <[email protected]> Wed, 1 Jan 2014 22:52:39 -0500
Newsgroups gmane.network.jabber.user
Message-ID <CALm9TZ9m=fbtyA-pCsLaRfgTG7GkLWi9KQqQywCiDgJ7uBUZ7g@mail.gmail.com>
On Tue, Dec 31, 2013 at 6:39 AM, Randolph <[email protected]> wrote:
> Why is the manifest
> https://github.com/stpeter/manifesto/blob/master/manifesto.txt
> not adding end-to-end encryption?
>

The manifesto is focused on short-term quickly achievable goals. From
the manifesto itself:

> This commitment to encrypted connections is only the first step
> toward more secure communication using XMPP, and does not obviate
> the need for technologies supporting end-to-end encryption (such as
> Off-the-Record Messaging or OTR), strong authentication, channel
> binding, secure DNS, server identity checking, and secure service
> delegation. Although we have worked to implement and deploy such
> technologies and will continue to do so, we believe that encrypting
> the traffic on the XMPP network is a necessary precondition to
> offering further security improvements.

So, end-to-end encryption is something we certainly want, along with a
bunch of other things, but it just isn't going to get done in the next
3-4 months (e2e can get pretty complex, and spec work is still
ongoing).

--
Waqas Hussain
_______________________________________________
This is JUser -- a mailing list for end users
of Jabber/XMPP clients.

To unsubscribe, send email to
[email protected]
or go to the following web
page, scroll all the way down,
and type in your email address:

http://mail.jabber.org/mailman/listinfo/juser
_______________________________________________