‘Off-the-Record’ Instant Messaging (Regaining privacy in online conversations)

Off-the-Record (OTR) Messaging allows you to have private conversations over instant messaging by providing:

  • Encryption - No one else can read your instant messages.
  • Authentication - You are assured the correspondent is who you think it is.
  • Deniability - The messages you send do not have digital signatures that are checkable by a third party. Anyone can forge messages after a conversation to make them look like they came from you. However, during a conversation, your correspondent is assured the messages he sees are authentic and unmodified.
  • Perfect forward secrecy - If you lose control of your private keys, no previous conversation is compromised.

Technical explanation (good starting point is: 17m22s)



You can achieve this by using the cross-platform (Windows, Linux; use Adium for Mac), multi-protocol (AIM, MSN, XMPP, etc) and open source instant messaging client Pidgin, and installing the OTR plugin.

Other OTR-enabled software. Configuring the OTR plugin web tutorial. Authenticating a chat buddy web tutorial.

Video tutorial

Short URL for this post: http://tmblr.co/ZJ0obwBZVqkV