« Previous - Version 4/32 (diff) - Next » - Current version
Adrian Georgescu, 09/13/2013 01:59 am


Blink OTR implementation

Blink SIP client for SIP2SIP edition is a multimedia SIP client that supports chat sessions using MSRP protocol (RFC4975 http://tools.ietf.org/html/rfc4975).

On top of MSRP session, Blink implements the OTR protocol.

OTR Protocol

Off-the-Record (OTR) Messaging allows you to have private conversations over instant messaging by providing:

Encryption

No one else can read your instant messages.

Authentication

You are assured the correspondent is who you think it is.

Deniability

The messages you send do not have digital signatures that are checkable by a third party. Anyone can forge messages after a conversation to make them look like they came from you. However, during a conversation, your correspondent is assured the messages he sees are authentic and unmodified.

Perfect forward secrecy

If you lose control of your private keys, no previous conversation is compromised.

Implementation

User input

  • Chat window has the Encryption toolbar icon, encryption features for each session can be controlled by clicking on this toolbar item, a contextual menu appears
  • Verification of remote identity can be performed using SMP protocol
  • Each Blink contact can have encrypted related attributes saved (always use OTR, verification status and learned fingerprint)

Notifications

When remote party has changed its encryption fingerprint several visual and audible clues appear:

  • Chat window system message is displayed
  • Voice synthesiser speaks
  • System notification (OSX >=10.8)
  • Growl notification