Re: Plaintext passwords
"Norman Rasmussen" <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Oct 10, 2008 at 6:12 PM, anders conbere <[email protected]> wrote: > > With the proposed requirement of TLS encryption when connecting to a > server, > > the plaintext requirement is only slightly relaxed -- you end up trusting > > the TLS layer to protect your password from attack. > > Which the rest of the world has agreed is a much safer assertion then > trusting server admins to keep the passwords safe. (see reddit for > example of leaking passwords). Frankly it's just a bad idea to store > the passwords in plain-text and the sooner that gets fixed not only in > the spec but as an understanding within the community the better. > I'm not sure sure... with the recent fuss around the new Firefox making it really-hard(tm) to accept a ssl cert that you don't recognize. I would think that any sort of Man-In-The-Middle DNS/TLS attack would have a very good chance of recovering the plain-text password. It really it moves the trust from a single point to per-user, i.e. who do you trust more - the server admin to keep the plaintext passwords secure, or joe blogs to not just-hit ok when his client complain that the server's cert is suddenly different. I suppose it's then the client authors that can really help out there, that the clients need to store the cert hash the first time the client connects (even with an approved CA - a little social engineering can get you one of these for a domain you don't own), and check it's the same cert next time. This is the way ssh works, and no one finds much fault with that. -- - Norman Rasmussen - Email: [email protected] - Home page: http://norman.rasmussen.co.za/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________