[Operators] omemo fingerprints

GDR! gdr at gdr.name
Thu Jun 1 08:17:49 UTC 2017


On Tue, 30 May 2017 16:53:47 +0300
Kev Stanz <medpracsupp at gmail.com> wrote:

> Hi all,
> 
> Does anybody know how omemo fingerprints are generated in Gajim? What
> do they depend on to be generated?
> 

Woah, that's a good question. I followed the path and I'd be happy if
someone proved me wrong, but it looks at a first sight that it's just
using os.urandom() which is not cryptographically secure.

https://dev.gajim.org/gajim/gajim-plugins/blob/master/omemo/omemo/liteaxolotlstore.py#L59
https://github.com/tgalal/python-axolotl/blob/master/axolotl/util/keyhelper.py#L21
https://github.com/tgalal/python-axolotl/blob/master/axolotl/ecc/curve.py#L25
https://github.com/tgalal/python-axolotl/blob/master/axolotl/ecc/curve.py#L15

TLDR: last link.


More information about the Operators mailing list