Comments on draft-alkemade-xmpp-iq-validation-00

"Joe Hildebrand (jhildebr)" <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <CF4096A9.3D005%[email protected]>
(no hats)

Section 1: suggest s/it was found//

Before Section 4: suggest adding some examples in a new section.  Good
iq/response, spoofed response with different from (perhaps followed by
real response to make it clear), unexpected 'from' from the server

Section 4: suggest switching the order of 4.1 and 4.2.  current section
4.1 is an edge case, leading with the core mechanism is more understandible

Section 4.1: quote 6120 and 3920 directly if possible.

Section 4.2: we had lots of discussion over "unique".  We'll likely want
some flavor of that discussion in the final text.  For the MUST ignore
text, can the client log an error or notify the user?

Section 6: we'll likely want some security analysis here.

May a server perform this tracking too, and reject things that look like
attacks?

This doc is a good start.  I think we should adopt it into the working
group immediately.

-- 
Joe Hildebrand
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.