Conversation
Notices
-
SSL only protects you from your device to the XMPP server. Then the !XMPP message is decrypted to plaintext, possibly logged, sent to your correspondent's server, possibly logged again, then to your correspondent. But #OTR encrypts the message completely from your device to your correspondent's. Each device has its own key, by design. If you lose your device your keys on other devices are not compromised. Please reconsider using OTR. I'll gladly correspond with people for practice: xmpp://bjonkman@sobac.com !crypto
-
@bobjonkman @benfell Currently, most #XMPP servers implement #SSL / #TLS both client-to-server and #server-to-server, but as mentioned, messages decrypted to plain text on each user’s server. Even if you self-host your server, your contacts may not. I consider #OTR a very important part of any !XMPP client.
-