Hi, I have a few outstanding questions/remarks about the crypto protocol part of OMEMO:
- The XEP says it uses the Olm protocol, but it also mentions signed pre-keys (which I assume are about X3DH, which Olm doesn't use). Either the X3DH bits should be removed, or we should document our 'fork' of the Olm protocol that uses X3DH. - Olm doesn't send the previous chain length with its messages. This makes it impossible to know whether or not there have been skipped message keys that need to be stored. Is this something we should add, is out-of-order messages something we don't need to deal with? Note that sending the previous chain length *is* part of the original Double Ratchet spec. - The XEP uses AES-128GCM for encryption of the payload. The payload itself is (I assume) an Olm encrypted message. Olm uses a combination of AES-CBC for encryption and HMAC-SHA256 for authentication. For consistency, can/should we replace the Olm encrypted message format with AES-GCM as well for both authentication and encryption? - Is there a specific reason for going with AES-128GCM instead of AES-256GCM? I'm asking for practical purposes, because some opinionated crypto libs such as NaCl and LibSodium only have the latter. Might be easier for implementations if AES-256GCM is taken. thanks, Remko
_______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
