Re: See-other-uri and insecure web sockets
Ben Campbell <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
Peter, Kevin, and Jonathan, In your opinions, is this sufficiently addressed in the current version of the draft? Thanks! Ben. On Mar 4, 2014, at 7:43 PM, Peter Saint-Andre <[email protected]> wrote: > On 3/4/14, 4:44 PM, Kevin Smith wrote: >> On Tue, Mar 4, 2014 at 3:31 PM, Jonathan Lennox <[email protected]> wrote: >>> As requested -- I reviewed the text forbidding see-other-uri downgrading in the current version of draft-ietf-xmpp-websocket, and I'm happy with it. >>> >>> What I was responding to at the mic was a comment that StPeter made during his presentation, suggesting that in addition, a future version of the draft would recommend that see-other-uri received over an insecure (ws or http) connection should be ignored. >> >> It feels to me like there are potentially auth mechanism downgrade >> attacks associated here, if people were to do the Wrong Thing. So I >> think at least a note is worthwhile. >> >> The document does, though, tell everyone to do wss, so this is >> arguably not an issue. > > Personally I see no harm in a bit of text that reinforces the point. > > Peter > > > _______________________________________________ > xmpp mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/xmpp