<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacklab.to &#187; im</title>
	<atom:link href="http://hacklab.to/archives/tag/im/feed/" rel="self" type="application/rss+xml" />
	<link>http://hacklab.to</link>
	<description>Toronto&#039;s hacker collective</description>
	<lastBuildDate>Fri, 03 Feb 2012 07:33:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Interesting MITM with otr conversation log</title>
		<link>http://hacklab.to/archives/interesting-mitm-with-otr-conversation-log/</link>
		<comments>http://hacklab.to/archives/interesting-mitm-with-otr-conversation-log/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 23:41:52 +0000</pubDate>
		<dc:creator>letoams</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[im]]></category>
		<category><![CDATA[otr]]></category>

		<guid isPermaLink="false">http://hacklab.to/?p=109</guid>
		<description><![CDATA[I got some strange IM from someone. Halfway through  I figure out we&#8217;ve been setup somehow with a relay in the middle and both of us see the other as some other identity. When the person says he is using adium, I thought it was a perfect chance to fire up OTR to see what [...]]]></description>
			<content:encoded><![CDATA[<p>I got some strange IM from someone. Halfway through  I figure out we&#8217;ve<br />
been setup somehow with a relay in the middle and both of us see the<br />
other as some other identity. When the person says he is using adium, I<br />
thought it was a perfect chance to fire up OTR to see what would happen<br />
with this MITM scenario&#8230;.  Funny enough, it revealed the identity of<br />
the other user to me :)</p>
<p>(My AIM identity is letoams)</p>
<p>(06:17:38 PM) SensitiveCoho: Hey.<br />
(06:18:16 PM) letoams: bot?<br />
(06:18:36 PM) SensitiveCoho: are you a bot?<br />
(06:18:53 PM) letoams: are you are you are you a bot?<br />
(06:19:14 PM) SensitiveCoho: no<br />
(06:19:17 PM) SensitiveCoho: i&#8217;m human<br />
(06:19:28 PM) letoams: ok then<br />
(06:19:57 PM) SensitiveCoho: who are you?<br />
(06:20:13 PM) letoams: if you dont know why are you talking to me?<br />
(06:20:26 PM) SensitiveCoho: i want to know why you&#8217;re talking to me<br />
(06:20:48 PM) letoams: you started?<br />
(06:20:52 PM) letoams: (06:17:38 PM) SensitiveCoho: Hey.<br />
(06:21:12 PM) SensitiveCoho: i&#8217;m not SensitiveCoho<br />
(06:21:30 PM) letoams: that&#8217;s what i see<br />
(06:21:31 PM) SensitiveCoho: embarrassedcoho<br />
6:17</p>
<p>Hi!<br />
(06:21:40 PM) SensitiveCoho: i see you as &#8220;embarrassedcoho&#8221;<br />
(06:21:48 PM) letoams: that&#8217;s not my name :)<br />
(06:22:00 PM) letoams: funny. must be some bot connecting two random im<br />
identities<br />
(06:22:06 PM) SensitiveCoho: maybe<br />
(06:22:20 PM) SensitiveCoho: you on mac/pc?<br />
(06:22:27 PM) letoams: linux<br />
(06:22:32 PM) SensitiveCoho: i&#8217;m on mac<br />
(06:22:33 PM) letoams: not infected here :P<br />
(06:22:37 PM) SensitiveCoho: using adium<br />
(06:22:57 PM) SensitiveCoho: adium&#8217;s been weird today &#8230; bugging me that yahoo<br />
messenger network is down for mainenance<br />
(06:23:00 PM) letoams: really? let&#8217;s try otr then. that would defeat a man in<br />
the middle attack<br />
(06:23:02 PM) SensitiveCoho: it just keeps telling me this over and over<br />
(06:23:03 PM) Attempting to start a private conversation with SensitiveCoho&#8230;<br />
(06:23:12 PM) SensitiveCoho: otr?<br />
(06:23:14 PM) sensitivecoho has not been authenticated yet.  You should<br />
authenticate this buddy.<br />
[Image] (06:23:14 PM) Unverified conversation with SensitiveCoho started.<br />
(06:23:26 PM) The following message received from sensitivecoho was not<br />
encrypted: [error]<br />
(06:23:29 PM) The following message received from sensitivecoho was not<br />
encrypted: [hmm]<br />
(06:23:30 PM) letoams: its privacy crypto built into adium and pidgin<br />
(06:23:33 PM) OTR Error: You sent encrypted data to logicbus, who wasn&#8217;t<br />
expecting it.<br />
(06:23:45 PM) Successfully refreshed the unverified conversation with<br />
SensitiveCoho.<br />
(06:23:45 PM) The last message to sensitivecoho was resent.<br />
(06:23:47 PM) letoams: haha<br />
(06:23:47 PM) The following message received from sensitivecoho was not<br />
encrypted: [could this be due to a compromised password?]<br />
[Image] (06:23:53 PM) Private conversation with SensitiveCoho lost.<br />
(06:23:56 PM) OTR Error: You sent encrypted data to logicbus, who wasn&#8217;t<br />
expecting it.<br />
(06:23:59 PM) SensitiveCoho: i can&#8217;t read what you&#8217;re saying<br />
(06:24:02 PM) OTR Error: You sent encrypted data to logicbus, who wasn&#8217;t<br />
expecting it.<br />
(06:24:03 PM) letoams: awesome. the MITM does otr too<br />
(06:24:20 PM) sensitivecoho is contacting you from an unrecognized computer.<br />
You should authenticate this buddy.<br />
[Image] (06:24:21 PM) Unverified conversation with SensitiveCoho started.<br />
(06:24:23 PM) The following message received from sensitivecoho was not<br />
encrypted: [i read that]<br />
[Image] (06:24:29 PM) Private conversation with SensitiveCoho lost.<br />
(06:24:38 PM) SensitiveCoho: very strange<br />
(06:24:40 PM) letoams: i think we blew up the mitm thing.<br />
(06:25:06 PM) letoams: you know anyone in Toronto?<br />
(06:29:13 PM) The encrypted message received from sensitivecoho is unreadable,<br />
as you are not currently communicating privately.<br />
[Image] (06:29:34 PM) Unverified conversation with SensitiveCoho started.<br />
[Image] (06:29:34 PM) Unverified conversation with SensitiveCoho started.<br />
[Image] (06:32:21 PM) Private conversation with SensitiveCoho lost.<br />
(06:32:27 PM) letoams: is your handle logicbus ?<br />
(06:32:41 PM) The encrypted message received from sensitivecoho is unreadable,<br />
as you are not currently communicating privately.<br />
(06:33:02 PM) SensitiveCoho: how did you figure that out<br />
(06:33:11 PM) letoams: (06:23:33 PM) OTR Error: You sent encrypted data to<br />
logicbus, who wasn&#8217;t expecting it.<br />
(06:33:15 PM) letoams: otr told me<br />
(06:33:26 PM) SensitiveCoho: hmm<br />
(06:33:34 PM) SensitiveCoho: i just see &#8220;embarrassedcoho&#8221; for those msgs<br />
(06:33:44 PM) SensitiveCoho: i suppose that could be a client thing<br />
(06:33:49 PM) SensitiveCoho: i guess you have an advantage over me<br />
(06:34:08 PM) letoams: still curious what is going on here. (my AIM is letoams)<br />
(06:34:16 PM) SensitiveCoho: yeah<br />
(06:34:41 PM) SensitiveCoho: i googled embarrassedcoho<br />
(06:34:48 PM) SensitiveCoho: didn&#8217;t come up with anything helpful<br />
(06:35:42 PM) letoams: me neither<br />
(06:36:22 PM) letoams: anyway. gotta go. have a nice life :)<br />
(06:36:35 PM) SensitiveCoho: peace</p>
<p>Anyone what this double-blind bot MITM thing is? Someone&#8217;s research project?</p>
]]></content:encoded>
			<wfw:commentRss>http://hacklab.to/archives/interesting-mitm-with-otr-conversation-log/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

