Improved user authentication in off-the-record messaging

  • Authors:
  • Chris Alexander;Ian Goldberg

  • Affiliations:
  • University of Waterloo, Waterloo, ON, Canada;University of Waterloo, Waterloo, ON, Canada

  • Venue:
  • Proceedings of the 2007 ACM workshop on Privacy in electronic society
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Instant Messaging software is now used in homes and businesses by a wide variety of people. Many of these users would benefit from additional privacy, but do not have enough specialized knowledge to use existing privacy-enhancing software. There is a need for privacy software to be easy to understand, with complicated cryptographic concepts hidden from the user. We look at improving the usability of Off-the-Record Messaging, a popular privacy plugin for instant messaging software. By using a solution to the Socialist Millionaires' Problem, we are able to provide the same level of privacy and authentication as in older versions of OTR, but we no longer require that the user understand any difficult concepts such as keys or fingerprints.