Feeds

Paradigms for Paranoids

Off-the-record messaging

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

Codecon 2005 The fourth annual CodeCon - "a workshop for developers of real-world applications that support individual liberties" - convened Friday afternoon (11 Feb) at Club NV (envy, not Nevada), amid ghostly laptop panels hovering in violet-tinted danceclub murk.

First-day registrations reached a respectable 90 (at $80 each), with more expected as the weekend progresses.

The highlight among the first day's five presentations was Ian Goldberg and Nikita Borisov on Off-the-Record Messaging (OTR), where 'messaging' can be instant messaging in any of its various formats, including online games, and "off the record" is meant to emulate as closely as possible the realworld strategy of sneaking off somewhere private, where you can talk with absolutely no record of what you said that might come back later to haunt you. (I was reminded of Maxwell Smart's ill-omened Cone of Silence.)

Conventional crypto technologies are optimised for (e.g.) enduring longterm contracts, but OTR prefers that messages be written as if in sand, via "perfect forward secrecy" (PFS) and "repudiable authentication". (Even if your conversation is cracked and transcribed, the programmers have included a "forgery toolkit" that allows you to repudiate such transcripts as trivial to forge.)

With such glorious levels of intimate distrust, I was surprised Ian didn't name his exemplary chatterers "Bill" and "Monica" - both Ian and Nikita were witty presenters, with the former doing funny voices, and the latter offering, when a projector bulb blew during their demo, to substitute an interpretive dance.

Another maniacally brilliant twist is that they can invisibly solicit OTR dialogs from strangers in chat by appending an inconspicuous all-whitespace flag, consisting of a characteristic arrangement of 24 spaces and tabs. And it was a pleasure, as well, to hear the consistently high level of followup questions after their talk.

Other first-day presentations: Hal Finney on digital cash ("The owner of the server is the enemy"), David Reid and Ben Laurie of Apache on adding group-based access controls to the certification process, Walter Landry's exhaustive comparative benchmarking of distributed version-control apps (due to be posted here), and Cat Okita on reputation management.

See the schedule and program for details. ®

Related story

How to isolate DNA with salad-spinner

The essential guide to IT transformation

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
China hopes home-grown OS will oust Microsoft
Doesn't much like Apple or Google, either
Linux turns 23 and Linus Torvalds celebrates as only he can
No, not with swearing, but by controlling the release cycle
This is how I set about making a fortune with my own startup
Would you leave your well-paid job to chase your dream?
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Eat up Martha! Microsoft slings handwriting recog into OneNote on Android
Freehand input on non-Windows kit for the first time
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?