Reading the Crypto Classics: Borisov, Goldberg, and Brewer „Off-the-Record Communication, or, Why Not To Use PGP“

22.09.2021 10:00-11:00

Moderator: Rune Fiedler (TU Darmstadt, Cryptoplexity Group) | Location: Online

Organizer: Christian Janson, TU Darmstadt, Cryptoplexity Group


This is the last talk in the seminar series „Reading the Crypto Classics“ for the summer term 2021. The idea of this seminar is to jointly read classical milestone papers in the area of cryptography, to discuss their impact and understand their relevance for current research areas. The seminar is running as an Oberseminar, but at the same time meant to be a joint reading group seminar of the CROSSING Special Interest Group on Advanced Cryptography with all interested CROSSING members being invited to participate.

This issue will cover the paper

Borisov, Goldberg, and Brewer „Off-the-Record Communication, or, Why Not To Use PGP“ (WPES 2004); available at

with the following abstract:

„Quite often on the Internet, cryptography is used to protect private, personal communications. However, most commonly, systems such as PGP are used, which use long-lived encryption keys (subject to compromise) for confidentiality, and digital signatures (which provide strong, and in some jurisdictions, legal, proof of authorship) for authenticity.

In this paper, we argue that most social communications online should have just the opposite of the above two properties; namely, they should have <i>perfect forward secrecy</i> and <i>repudiability</i>. We present a protocol for secure online communication, called “off-the-record messaging„, which has properties better-suited for casual conversation than do systems like PGP or S/MIME. We also present an implementation of off-the-record messaging as a plugin to the Linux GAIM instant messaging client. Finally, we discuss how to achieve similar privacy for high-latency communications such as email.“

