RE: "POP3 SASL Authentication Mechanism" submitted for publication
Lyndon Nerenberg <[email protected]> Mon, 15 Jan 2007 12:28:00 -0800 (PST)
| Newsgroups | gmane.ietf.pop3ext,gmane.ietf.sasl |
|---|---|
| Organization | The Frobozz Magic Homing Pigeon Company |
| Message-ID | <[email protected]> |
On Mon, 15 Jan 2007, Paul Leach wrote: > I worry that having TLS+PLAIN be the MTI sends an implicit message that > it is "good enough". I really think that all use of plain text > passwords, even over an encrypted tunnel to a trusted party, should be > discouraged. (At the very least, a stern passage in the security > considerations section is needed.) It is well known that users use the > same password on many different servers, so TLS+PLAIN lets any such > server act as the user to any other server. I strongly agree with this. In many corporate environments this sort of password re-use is enforced behaviour, mandated by corporate "security" policy. Strange, but true. --lyndon Never look at the trombones. You'll only encourage them. -- Robert Strauss, on conducting