It is no secret to anyone that, nowadays, the failure of instant messaging applications in terms of security, has been remarkably maximized by the number of immoral people operating in the net. So even private conversations between two users may end up in the hands of a third party and so, remove the confidentiality of such chats at all.
In this sense, it is pointed out that the messaging platforms are different that, due to different security gaps, they do not protect the confidential, personal or professional information that they handle of their users; Well, many messages do not reach their true recipients, but end up in the hands of others. For that reason, the famous OTR protocol has been created.
Thus, it refers to a protocol that was designed to avoid said existing interference and, in addition, ensure communications at a high level. Therefore, it is worth knowing what is this tool that protects information about, like how it works, what are its advantages and disadvantages, in addition to distinguishing the main messaging apps that are supported by the protocol “Off The Record”.
What is the Record OTR or Off protocol and what is it for in computing?
Also know as “Off The Record Messaging”, the OTR is defined as a cryptographic protocol for confidential or unofficial messaging which basically offers strong encryption to protect conversations made through an instant messaging platform. Therefore, it consists of a computer tool that serves to safeguard all the information transmitted by messages through an app.
In this sense, to guarantee said security, the Off The Record protocol makes use of a combination between the renowned AES symmetric key algorithm and the Diffie-Hellman key exchange protocol together with the SHA-1 function.
In such a way, it provides optimal encryption and authentication, Like a great direct confidentiality. Therefore, regardless of the instant messaging platform that the user uses, the OTR protocol takes care of encrypting all shared messages. Well, by default, this is a tool focused on protect information. Thanks to that, no meddler will be able to spy on the messages sent under said computer protocol.
Application How does this protocol work and what are its characteristics?
Regarding the operation of this protocol originated by Ian Goldberg and Nikita Borisov, a couple of renowned cryptographers; We emphasize that, as soon as OTR is installed, all messages acquire rigorous coding derived from the combination of the different security methods used to safeguard them. Therefore, from the moment the sender shares his message, this will be encrypted and, exclusively when it reaches the receiver, it will be decrypted.
For his part, all this is carried out no matter how many servers are used to transport the message from your computer to that of your contact. Taking into account that, when applying it, the Off The Record protocol uses encryption / decryption keys that are generated only when required and later discarded. Which is why, even when people have finished the encrypted chat, no one will be able to reread the messages that have been sent in it.
Among other details, it is also necessary to know what the main characteristics of the OTR are and that is why, below, we name the most interesting of all:
- One of the main peculiarities of this protocol, is that he takes care of provide encryption and authentication in instant messaging environments.
- For nature, the OTR provides perfect secret confidentiality to all users, thanks to the use of the Diffie-Hellman key exchange protocol.
- This protocol too is based on hiding identity, both from the sender and the receiver.
- Luckily it works with total efficiency, regardless of the instant messaging platform that people use.
- Regarding its installation, Notably, is dependent on each operating system.
What are the benefits of using OTR to encrypt IM communications?
Of course, thanks to your performance and its optimized characteristics for encrypt communications made by instant messaging, the protocol Off the record provides big benefits to its users, in terms of security and privacy.
Which are points in favor that are worth knowing in detail and, therefore, we mention them here:
- Supports mutual authentication between users by means of a shared secret from the millionaire socialist. Thanks to this, it guarantees the verification of the identity of the people remotely and prevents the execution of malicious actions by an intermediary.
- Due to its perfect secret confidentiality, it focuses on the messages transmitted are encrypted with a unique AES temporary key and so, increases security. Whereas, said key is provided by the key exchange protocol.
- There are no risks in terms of message forgery that apparently comes from another of the chat participants. Therefore, the receiver will be able to be completely sure that the message received was delivered. by the person you have identified.
- At all times, the privacy of the conversation is truly protected. Which means that, even if an encrypted conversation under this protocol has been ended, no one will have the possibility to reread the messages shared through that chat (not even the people who have participated).
Limitations of Off The Record What are the weak points of this protocol?
But, since nothing is perfect, the protocol OTR instant messaging too reveals some cons, cons, or limitations that must be taken into consideration.
Therefore, in this section of the post, we proceed to mention the weakest points that this protocol exhibits, so far:
- Since 2009, the OTR protocol does not support multi-user conversations, although it could be implemented in the future (no specific date). This being the most notable disadvantage of Off The Record.
- It is imperative that, the person with whom you want to exchange encrypted messages, also have OTR protocol installed to be able to use it effectively. However, it is a limitation that can be fixed by simply downloading an app that supports this tool.
- Unfortunately, the Off The Record does not have support for encrypted audio or video. What’s more, this condition has not even been planned by experts.
- Previous versions to OTR 4.0.0, do not allow multiple conversations with the same user you have logged into different sites.
List of messaging apps protected with OTR that you should know
As we mentioned before, when you use an instant messaging application protected with Off The Record, no need to verify if the receiver has installed this technology.
Therefore, it is really useful to make use of this type of apps and, below, we mention 3 of them:
Adium
Compatible with Mac OS X, it is an instant messaging application that has the ability to connect to the networks of MSN, Yahoo, Gtalk, Jabber, AIM, etc. Thus, it is characterized by being an open source program that supports numerous protocols from a library suitable for instant messaging programming, called “libpurple”.
For its part, one of the greatest advantages of Adium, is that, can be custom configured and accepts different plugins to optimize the experience. In such a way, there is the possibility of adding new functions and giving it a better appearance. In addition to this, it is ideal for group all messaging accounts in a single application. But, it does not have video or audio support.
Download Adium MacOS
Meet.Jit.si
It consists of an application that has support for Windows, Mac OS X and Linux through the Web, in order to provide instant messaging, VoIP and video conferencing tool to millions of users around the world. In this sense, thanks to the fact that it is compatible with the OTR protocol, guarantees great security and even provides encryption with SRTP and ZRTP protocols.
For its part, it allows desktop streaming, offers an auto-correction function, is ideal for make call recordings, has an attended and / or blind call transfer, as well as change to automatic “away”. In addition, it provides a storage of encrypted passwords with a master key and supports broadband telephony.
TextSecure
To conclude this list, we emphasize TextSecure Which refers to a totally free and open source application, available on the Google Play Store. Therefore, it only has compatibility with equipment Android. In this way, it provides its users with broad privacy to share SMS or MMS, since encrypt messages with a password and thus, these remain safe even when the mobile has been lost.
In addition, since it supports the Off The Record protocol, the app is also characterized by encrypt messages so that no one has the ability to read them. For even more advantage, employs cryptography In order to ensure security, it is compatible with WhatsApp, allows establish automatic messages with secure connection, etc.