On 19 September 2017 at 09:21, Klaus Herberth <[email protected]> wrote:
>> Hi Klaus,
> Hi Andrey,
>
>
>> What do you mean by "libsignal"? There are at least 4(+1) libraries:
> With libsignal I referred to your linked implementations of WhisperSystems.
>
>> Note, javascript favor is already available.
> I know, but it is GPL and this doesn't work for everyone.
>
>> BTW, why is it terrible?
> It's terrible, because the wire format of those implementations aren't
> documented (as far as I know) and therefore it's quite hard to implement
> such protocol by your own. I think a protocol should be like an Internet
> Standard defined in RFC1310:
>
>      "In general, an Internet Standard is a specification that is stable
>       and well-understood, is technically competent, has multiple,
>       independent, and interoperable implementations with operational
>       experience, enjoys significant public support, and is recognizably
>       useful in some or all parts of the Internet."
>
> I think "multiple independent and interoperable implementations" are
> currently missing for the "signal protocol". If we would have some kind
> of documentation for the wire format and a clear hint in the XEP that
> libsignal is needed it would be a great help for everyone who wants to
> implement this XEP.
>

I entirely and unreservedly agree with you.

For what its worth, the XMPP Council originally rejected this XEP
because it was reliant on a single library; while we were assured that
this was not the case anymore, and anyone could easily (I believe the
word "trivially" was used multiple times) implement a fully
independent implementation and have it interoperate, you are sadly
proving that this is not the case.

>> It's not that uncommon a program can be compiled only with openssl
>> (and even not with the latest version).
> Please correct me if I'm wrong, but everything in openssl is documented
> somewhere. There is no magic happening inside this library and therefore
> the comparison doesn't work. Also openssl is under Apache License which
> makes it a lot easier to use it in combination with other software.

As far as I am aware, OpenSSL is based entirely on well-known and
fully documented protocols and algorithms. Even the API has some
documentation, increasingly accurate as well these days. There are
numerous TLS libraries, and numerous implementations of the
cryptographic primitives used by OpenSSL. I, like you, have no idea
why anyone would consider this a useful comparison.

Dave.
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to