Re: See-other-uri and insecure web sockets

Ben Campbell <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <[email protected]>
Peter, Kevin, and Jonathan,

In your opinions, is this sufficiently addressed in the current version of the draft?

Thanks!

Ben.


On Mar 4, 2014, at 7:43 PM, Peter Saint-Andre <[email protected]> wrote:

> On 3/4/14, 4:44 PM, Kevin Smith wrote:
>> On Tue, Mar 4, 2014 at 3:31 PM, Jonathan Lennox <[email protected]> wrote:
>>> As requested -- I reviewed the text forbidding see-other-uri downgrading in the current version of draft-ietf-xmpp-websocket, and I'm happy with it.
>>> 
>>> What I was responding to at the mic was a comment that StPeter made during his presentation, suggesting that in addition, a future version of the draft would recommend that see-other-uri received over an insecure (ws or http) connection should be ignored.
>> 
>> It feels to me like there are potentially auth mechanism downgrade
>> attacks associated here, if people were to do the Wrong Thing. So I
>> think at least a note is worthwhile.
>> 
>> The document does, though, tell everyone to do wss, so this is
>> arguably not an issue.
> 
> Personally I see no harm in a bit of text that reinforces the point.
> 
> Peter
> 
> 
> _______________________________________________
> xmpp mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/xmpp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.