On Tuesday 27 March 2007, Martijn Klingens said:
> On Tuesday 27 March 2007 14:36, F. Scheffold wrote:
> > That is not possible because the encryption key is only valid during the
> > chat session.
>
> Hmm. That complicates matters. :(
>
> > One possibility would be to inform the user when he enables an otr chat
> > session that history logs the messages. If he don't want that he could
> > disable the history plugin. What do you think?

1) start the chat session with an infomessage "Logging disabled for this 
session"

> Perhaps it's possible to have a "bypassing" mechanism that history won't
> log OTR messages but still logs everything else? In that case it is a
> checkbox 'Allow logging of messages' in the properties for OTR.

2) Rearrange the messagehandler chain for the chat session to remove the 
history plugin by default

3) Provide a toolbar button to replace it if the OTR user decides he does in 
fact want a record of the chat (very sneaky, Ms. Tripp!)

> Maybe even better is to extend Kopete::Message with a flag that marks a
> message as 'sensitive' or 'encrypted' and then give History an option 'Log
> encrypted messages as plain text' that can apply to both GPG and OTR?

Might be an option, but History would need to point out that OTR encrypted 
messages are not recoverable.  

OTR guarantees deniability, doesn't it?  'I never talked to that blonde Zdnet 
journalist, honest!'  If so, storing the encrypted message contents with the 
sender would break that property.

Will
_______________________________________________
kopete-devel mailing list
[email protected]
https://mail.kde.org/mailman/listinfo/kopete-devel

Reply via email to