Re: Plaintext passwords
Simon Friedberger <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
Hi Norman, thanks for your answer! Just to make sure I understand correctly: > Because it makes it simpler and easier to make it possible to confirm that > the client knows the same password without having send it over the wire when > authenticating, (or encrypt it before sending). > Another reason is that it doesn't matter how the password is encrypted, if > the jabber server binary can read it, then so can the server admin. What kind of verification procedure do you have in mind? Why not send a hash as usual? The same problem holds for all password authentication systems. Again it is usually solved using a hash. > The only non-plaintext storage that makes any sense, is probably digest-md5. > Although then the only way to 'upgrade' a password from say md5 to sha1, if > for the client to provide a plaintext password - which is what we're trying > to avoid. Why would anybody want to 'upgrade' a password to a different hash? Assuming the hash is broken new passwords should be given out anyway. Thanks for your help! Ciao Simon _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________