Re: IQ Handling vulnerabilities
Dave Cridland <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <CAKHUCzwFxx-xOzVyYFzGdf_MBrgaWOAdWUQq2O3X3ADNCqivcQ@mail.gmail.com> |
On Mon, Feb 10, 2014 at 8:22 PM, Dave Cridland <[email protected]> wrote: > The advantage here isn't really in the <iq/> case we've been mostly > discussing, but the other cases of a returned id - since we don't want to > track outbound directed presence, or message, ids for an arbitrary length > of time. (I assume). > > Just to summarize a chat I had with Joe on this; neither of us can immediately think of any attack based on bounced presence or message, but no doubt Thijs will ruin my complacency. There's no need, even if such an attack exists, to actually mandate a particular format or generation strategy, of course - there's no interop need here - but a recommendation along the lines of XEP-0185 might be useful. Dave. _______________________________________________ xmpp mailing list [email protected] https://www.ietf.org/mailman/listinfo/xmpp