Re: See-other-uri and insecure web sockets
Peter Saint-Andre <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
On 3/4/14, 4:44 PM, Kevin Smith wrote: > On Tue, Mar 4, 2014 at 3:31 PM, Jonathan Lennox <[email protected]> wrote: >> As requested -- I reviewed the text forbidding see-other-uri downgrading in the current version of draft-ietf-xmpp-websocket, and I'm happy with it. >> >> What I was responding to at the mic was a comment that StPeter made during his presentation, suggesting that in addition, a future version of the draft would recommend that see-other-uri received over an insecure (ws or http) connection should be ignored. > > It feels to me like there are potentially auth mechanism downgrade > attacks associated here, if people were to do the Wrong Thing. So I > think at least a note is worthwhile. > > The document does, though, tell everyone to do wss, so this is > arguably not an issue. Personally I see no harm in a bit of text that reinforces the point. Peter