Re: Plaintext passwords

"Norman Rasmussen" <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On Fri, Oct 10, 2008 at 6:12 PM, anders conbere <[email protected]> wrote:

> > With the proposed requirement of TLS encryption when connecting to a
> server,
> > the plaintext requirement is only slightly relaxed -- you end up trusting
> > the TLS layer to protect your password from attack.
>
> Which the rest of the world has agreed is a much safer assertion then
> trusting server admins to keep the passwords safe. (see reddit for
> example of leaking passwords). Frankly it's just a bad idea to store
> the passwords in plain-text and the sooner that gets fixed not only in
> the spec but as an understanding within the community the better.
>

I'm not sure sure... with the recent fuss around the new Firefox making it
really-hard(tm) to accept a ssl cert that you don't recognize.  I would
think that any sort of Man-In-The-Middle DNS/TLS attack would have a very
good chance of recovering the plain-text password.

It really it moves the trust from a single point to per-user, i.e. who do
you trust more - the server admin to keep the plaintext passwords secure, or
joe blogs to not just-hit ok when his client complain that the server's cert
is suddenly different.  I suppose it's then the client authors that can
really help out there, that the clients need to store the cert hash the
first time the client connects (even with an approved CA - a little social
engineering can get you one of these for a domain you don't own), and check
it's the same cert next time.   This is the way ssh works, and no one finds
much fault with that.

-- 
- Norman Rasmussen
- Email: [email protected]
- Home page: http://norman.rasmussen.co.za/

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.