Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Key warning when initiating echo chat #440

Closed
Norbert80 opened this issue May 29, 2015 · 8 comments
Closed

Key warning when initiating echo chat #440

Norbert80 opened this issue May 29, 2015 · 8 comments
Assignees
Labels
bug Something isn't working
Milestone

Comments

@Norbert80
Copy link

Kontalk lists myself as contact. I started a conversation with myself. First I had to confirm a red message about accepting changed keys. Now I get my own echo. :-)

@Norbert80 Norbert80 changed the title Can Chat with myself Can chat with myself May 29, 2015
@webratte
Copy link
Contributor

As far as i know it's a feature not a bug ;-)
I like it for making me memos.
I hope it will stay also in future versions.

@Norbert80
Copy link
Author

This is a messenger. Not a memo tool... ts

@daniele-athome
Copy link
Member

Writing to yourself is perfectly normal for an XMPP service, especially because it allows you to exchange messages and data between all the devices connected to the account.
The key warning might be a bug instead. I'll investigate.

@daniele-athome daniele-athome self-assigned this May 29, 2015
@daniele-athome daniele-athome added the pending Issue is pending further analysis label May 29, 2015
@Norbert80 Norbert80 changed the title Can chat with myself Key warning when initiating echo chat May 29, 2015
@daniele-athome daniele-athome added bug Something isn't working and removed pending Issue is pending further analysis labels May 29, 2015
@daniele-athome daniele-athome added this to the 3.0 milestone May 29, 2015
@webratte
Copy link
Contributor

@Norbert80 I'm using this feature still this way and I like it :-P

I'm also use it to send me memos to (e.g. Hyperlinks) my PC via Kontalk Desktopclient (like @daniele-athome said).

@Norbert80
Copy link
Author

@webratte there are apps like Google Keep that are synchronising.

@webratte
Copy link
Contributor

@Norbert80 Maybe. But why should I install another App if Kontalk do the same work for me? ;-)

But I think this is not the right place for this discussion.
There are forums in the www for thing like this :-)
I will stop it now.

@Norbert80
Copy link
Author

@daniele-athome does your patch just accept each key when chatting with onselfe? Or does it really use the local stored key?

Background of my question is to ensure to recognise man-in-the-middle attacks also for echo chats.

@daniele-athome
Copy link
Member

@Norbert80 it uses the server-provided key for encrypting, but it still uses the local key for decrypting. That way, if decryption or signature verification fail, you're probably facing a MITM attack. Although the user is not explicitly warned in this case (just the usual red alert badge on the message; you need to open message details to know more).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants