Bug 533855 - RFE: Empathy does not support OTR encryption
Summary: RFE: Empathy does not support OTR encryption
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: empathy
Version: 12
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Peter Gordon
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-11-09 14:41 UTC by Gregory Maxwell
Modified: 2009-11-16 13:23 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2009-11-09 19:20:50 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
GNOME Bugzilla 545347 0 None None None Never

Description Gregory Maxwell 2009-11-09 14:41:15 UTC
Description of problem:
In Fedora 12 Empathy replaced pidgin in the default install. 

Empathy does not provide support for OTR (as in libotr and pidgin-otr packages; http://www.cypherpunks.ca/otr/)

Most IM protocols provide no built in security. No widely used IM protocol currently provides end to end encryption without add-ons.  OTR is supported by many popular IM clients (in particular the very popular Adium client on OSX)

Site policy here prohibits using non-encrypted commercial IM services, so now in F12 a non-standard IM client must be used.

Comment 1 Brian Pepple 2009-11-09 15:37:03 UTC
Upsteam is aware, and it's on the roadmap for the future.
http://live.gnome.org/Empathy/FAQ#head-2a8a99485ca78dae8e8771575fa5005ac7c28b57

Comment 2 Gregory Maxwell 2009-11-09 17:07:53 UTC
Brian, your link is a statement from upstream that they won't support it: "We don't think that layering encrypted messaging on top of protocols that don't support it is very useful,".

It instead advances an approach (XTLS) for which there are no existing implementations (as far I can tell; it's a very new IETF draft), which is tied to the Jabber protocol, which does not provide the same cryptographic guarantees (no denyability, for example), and which will likely have severe usability problems as it depends on the users having x509 certificates (while OTR supports SSH style sticky auth plus optional secure secret exchange authentication).

Comment 3 Brian Pepple 2009-11-09 19:20:50 UTC
Correct. I took your bug as supporting encryption, not OTR.  Going to close this bug as WONTFIX since upstream doesn't plan on supporting this.  If OTR is mission critical for you, pidgin is still available in the repo.

Comment 4 Jonathan Blandford 2009-11-16 13:23:37 UTC
[ Note that upstream has since changed their mind on that, and claims to be considering how to include OTR.  In the short run though, its gotta be pidgin. ]


Note You need to log in before you can comment on or make changes to this bug.