Re: Plaintext passwords

"anders conbere" <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On Fri, Oct 10, 2008 at 9:30 AM, Norman Rasmussen
<[email protected]> wrote:
> On Fri, Oct 10, 2008 at 6:12 PM, anders conbere <[email protected]> wrote:
>>
>> > With the proposed requirement of TLS encryption when connecting to a
>> > server,
>> > the plaintext requirement is only slightly relaxed -- you end up
>> > trusting
>> > the TLS layer to protect your password from attack.
>>
>> Which the rest of the world has agreed is a much safer assertion then
>> trusting server admins to keep the passwords safe. (see reddit for
>> example of leaking passwords). Frankly it's just a bad idea to store
>> the passwords in plain-text and the sooner that gets fixed not only in
>> the spec but as an understanding within the community the better.
>
> I'm not sure sure... with the recent fuss around the new Firefox making it
> really-hard(tm) to accept a ssl cert that you don't recognize.  I would
> think that any sort of Man-In-The-Middle DNS/TLS attack would have a very
> good chance of recovering the plain-text password.
>
> It really it moves the trust from a single point to per-user, i.e. who do
> you trust more - the server admin to keep the plaintext passwords secure, or
> joe blogs to not just-hit ok when his client complain that the server's cert
> is suddenly different.  I suppose it's then the client authors that can
> really help out there, that the clients need to store the cert hash the
> first time the client connects (even with an approved CA - a little social
> engineering can get you one of these for a domain you don't own), and check
> it's the same cert next time.   This is the way ssh works, and no one finds
> much fault with that.

This is really also a strawman as there are beyond using TLS protocols
that allow the secure authentication of a user without passing any
re-usable secret across the wire (there are portions of Digest-MD5
that permit that kind of workflow for instance). There is simply no
reason in todays modern computing environment to believe that the
passwords you hand to a server admin will remain safe. Passwords are
stolen off of servers all the time, at least with ssl I'm given tools
to validate the authenticity of the server I'm connecting to.

~ Anders

>
> --
> - Norman Rasmussen
> - Email: [email protected]
> - Home page: http://norman.rasmussen.co.za/
>
> _______________________________________________
> JAdmin mailing list
> FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
> Forum: http://www.jabberforum.org/forumdisplay.php?f=19
> Info: http://mail.jabber.org/mailman/listinfo/jadmin
> Unsubscribe: [email protected]
> _______________________________________________
>
>
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.