Dev/Gajim

From Whonix
< Dev
Jump to navigation Jump to search


TODO[edit]

  • Gajim might intelligently set a Tor socks user name per account already. Do we still manually specify a user/password?
  • security
    • (3) TODO: create an AppArmor profile
  • does it have any protocol leaksarchive.org?
    • (4) TODO: check Gajim's built-in XML console
  • how to pre-configure Gajim with all these settings by default as a linux distribution?

Resolved[edit]

Was a blocker:

Done[edit]

  • Are uploads by gajim-httpupload encrypted using gajim-omemo?
    • Developer responded: "yes if you have activated OMEMO, httpupload will always encrypt the file, in fact you can not send a unencrypted file with OMEMO activated even if you wanted."
  • Plugin installer is only using https for verification which is weaker than gpg which is used by APT which is usually used to install software. [1] [2]

Discussion[edit]

  • it would take a lot patches to ensure that OMEMO encryption is always used, but on the other hand, because it is written in Python, Gajim is very easy to patch.
  • Gajim can keep its account username and passwords in

KeepassXcarchive.org using LibSecret integration. If we look at end-to-end security, and worry about the weakest links, then integration of IM with a password-manager should be a high priority.

Footnotes[edit]

We believe security software like Whonix needs to remain open source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!