I suggest you go dig up the old conversations from the archive on why
we made the 'change' to the siacs namespace.

TLDR; the 'siacs' XEP describes the current situation and people are
planning on doing some larger changes to OMEMO that might take a very
long time to complete. Thus we wanted to have an addressable (by
version number) state of the XEP that reflects the real world
situation.

For you there are basically two ways forward
a) To have something that works right now and is compatible with
existing implementations: Implement version 0.2 of the OMEMO protocol
that comes with a hard dependency on the signal protocol
b) Participate in the discussion / protocol development regarding
'OMEMO-NEXT' that will probably use its own double ratchet among other
improvements.

2017-09-18 15:27 GMT+02:00 Klaus Herberth <[email protected]>:
> Is there any explanation for the mentioned authentication tag?

Why we use an authentication tag? Because otherwise there is no direct
link between the authenticated signal whisper message and the cipher
text. w/o it anyone with the key can swap out the cipher text.

the auth tag is part of the gcm authenticated encryption scheme.

Future versions might use AES-CBC or something like that.
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to