[guardian-dev] potential Gibberbot bug with OTR initiation

Hans of Guardian hans at guardianproject.info
Fri Mar 1 11:53:42 EST 2013


When I log in with my desktop IM client, I get an OTR session that is initiated by the other side without them having started anything.  It just sets up an OTR session and then there is no message.  I've seen this twice in the past two days with Lee and Josh, who I think are both running the latest Gibberbot.  It happened with Lee when I logged into Pidgin, and with Josh when I signed into Adium.  So my guess is that its happening in Gibberbot.

For most people, this is only a minor annoyance, but it can be a privacy leak.

.hc


More information about the Guardian-dev mailing list