Re: WGLC of draft-ietf-xmpp-websocket-02

Ben Campbell <[email protected]> Fri, 6 Jun 2014 16:33:40 -0500
Newsgroups gmane.ietf.xmpp
Message-ID <[email protected]>
On Jun 6, 2014, at 3:36 PM, Lance Stout <[email protected]> wrote:

> 
>> Strictly as an individual, I then propose we either remove the mention entirely (my preference), or move it to an "implementation note" so that it cannot be conflated with the normative statement it's currently attached to.
>> 
>> But I realize that's pretty pedantic, and  if the authors are tired of making new versions, I can live with it as is :-)
> 
> Not tired. I've removed the offending parenthetical :-)
> 
> 
> However, I did amend the Security Considerations based on the prior discussion here, stating that if the XMPP over WebSocket service is provided as an intermediary between the XMPP server and client, then it SHOULD use an encrypted channel between itself and the XMPP server. Likewise, a client would need to use e2e encryption if it truly wants data privacy as there's no way to prove that the WS intermediary really is using encryption to the XMPP server. (The same considerations that apply for BOSH services)

WFM

Thanks!

Ben.

> 
> — Lance