Please consider using the signal and noise pipes protocols.
Signal (formerly axolotl) and noise are very good protocols, well-reviewed and offering very desirable features that go beyond what otr has to offer, e.g.:
- end-to-end encryption
- deniable authentication
- perfect forward secrecy
- future secrecy
- deniability of the conversation (of having exchanged messages at all)
- group chat encryption
(c.f. #50, but since that ticket is about threat model and not concrete protocols, I opened this ticket.
c.f. TokTok/c-toxcore#426 )
Ref: https://eprint.iacr.org/2016/1013.pdf https://whispersystems.org/docs/
ps.: the pre-keys exist to enable offline messaging, but they do not require a server at all, so it can work in a p2p system like tox as well.
Please consider using the signal and noise pipes protocols.
Signal (formerly axolotl) and noise are very good protocols, well-reviewed and offering very desirable features that go beyond what otr has to offer, e.g.:
(c.f. #50, but since that ticket is about threat model and not concrete protocols, I opened this ticket.
c.f. TokTok/c-toxcore#426 )
Ref: https://eprint.iacr.org/2016/1013.pdf https://whispersystems.org/docs/
ps.: the pre-keys exist to enable offline messaging, but they do not require a server at all, so it can work in a p2p system like tox as well.