Re: Plaintext passwords

Simon Friedberger <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
Hi Norman,

thanks for your answer!
Just to make sure I understand correctly:

> Because it makes it simpler and easier to make it possible to confirm that
> the client knows the same password without having send it over the wire when
> authenticating, (or encrypt it before sending).
> Another reason is that it doesn't matter how the password is encrypted, if
> the jabber server binary can read it, then so can the server admin.

What kind of verification procedure do you have in mind? Why not send a
hash as usual?
The same problem holds for all password authentication systems. Again it is
usually solved using a hash.

> The only non-plaintext storage that makes any sense, is probably digest-md5.
>  Although then the only way to 'upgrade' a password from say md5 to sha1, if
> for the client to provide a plaintext password - which is what we're trying
> to avoid.
Why would anybody want to 'upgrade' a password to a different hash?
Assuming the hash is broken new passwords should be given out anyway.

Thanks for your help!

Ciao
	Simon
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.