Re: See-other-uri and insecure web sockets
Kevin Smith <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <CAOb_Fnzw_dw3V5W2U5M6ch2k5d=HmpUdjBYbJJQSpkWKH=V+1w@mail.gmail.com> |
On Tue, Mar 4, 2014 at 3:31 PM, Jonathan Lennox <[email protected]> wrote: > As requested -- I reviewed the text forbidding see-other-uri downgrading in the current version of draft-ietf-xmpp-websocket, and I'm happy with it. > > What I was responding to at the mic was a comment that StPeter made during his presentation, suggesting that in addition, a future version of the draft would recommend that see-other-uri received over an insecure (ws or http) connection should be ignored. It feels to me like there are potentially auth mechanism downgrade attacks associated here, if people were to do the Wrong Thing. So I think at least a note is worthwhile. The document does, though, tell everyone to do wss, so this is arguably not an issue. > > I think this is a bad idea -- I don't see any reason why see-other-uri should be any less trusted than anything else received over an insecure connection. And indeed, I think that most servers (if they have a ws listener at all) would want to respond to insecure XMPP connections by sending a see-other-uri pointing at their wss uri! I think this scenario is somewhat unlikely - in this case the discovery would have pointed to was (either hard-coded or over 156 or whatever). /K