Opened 9 years ago

Closed 9 years ago

#11928 closed defect (invalid)

Buzz doesn't use OTR encryption

Reported by: Archimedes Owned by:
Milestone: Component: libpurple
Version: 2.7.0 Keywords: OTR Attention Buzz Encryption


When using the OTR plugin for secure conversations, the Attention/Buzz/Nudge? is send in plaintext instead of encrypted (at least in jabber, can't tell for other protocols as ICQ doesn't work atm):
(23:56:30) The following message received from archimedes@jabber.*.de was not encrypted: [Archimedes has buzzed you!]

Though this is just a minor leak of information, it should still be avoided to preserve complete privacy of the conversation.

I guess this is a libpurple bug, as both the button and the /buzz command show this behaviour.

In a short:

Steps to reproduce:

  1. Start a chat
  2. Enable OTR
  3. Send /buzz or click "Attention!" Button

What happes:
Buddy gets an *unencrypted* buzz message

What is expected:
Buddy gets an *encrypted* buzz message

Change History (1)

comment:1 Changed 9 years ago by QuLogic

  • Resolution set to invalid
  • Status changed from new to closed

This issue is caused by a third party plugin. We have no control over these plugins. Please report this problem to the authors of this third party plugin.

Note: See TracTickets for help on using tickets.
All information, including names and email addresses, entered onto this website or sent to mailing lists affiliated with this website will be public. Do not post confidential information, especially passwords!