RE: "POP3 SASL Authentication Mechanism" submitted for publication

Lyndon Nerenberg <[email protected]> Mon, 15 Jan 2007 12:28:00 -0800 (PST)
Newsgroups gmane.ietf.pop3ext,gmane.ietf.sasl
Organization The Frobozz Magic Homing Pigeon Company
Message-ID <[email protected]>
On Mon, 15 Jan 2007, Paul Leach wrote:

> I worry that having TLS+PLAIN be the MTI sends an implicit message that
> it is "good enough". I really think that all use of plain text
> passwords, even over an encrypted tunnel to a trusted party, should be
> discouraged. (At the very least, a stern passage in the security
> considerations section is needed.) It is well known that users use the
> same password on many different servers, so TLS+PLAIN lets any such
> server act as the user to any other server.

I strongly agree with this.  In many corporate environments this sort of 
password re-use is enforced behaviour, mandated by corporate "security" 
policy.  Strange, but true.


--lyndon

   Never look at the trombones. You'll only encourage them.
   			-- Robert Strauss, on conducting