See-other-uri and insecure web sockets
Jonathan Lennox <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
As requested — I reviewed the text forbidding see-other-uri downgrading in the current version of draft-ietf-xmpp-websocket, and I’m happy with it. What I was responding to at the mic was a comment that StPeter made during his presentation, suggesting that in addition, a future version of the draft would recommend that see-other-uri received over an insecure (ws or http) connection should be ignored. I think this is a bad idea — I don’t see any reason why see-other-uri should be any less trusted than anything else received over an insecure connection. And indeed, I think that most servers (if they have a ws listener at all) would want to respond to insecure XMPP connections by sending a see-other-uri pointing at their wss uri!