Re: Plaintext passwords
Peter Saint-Andre <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
anders conbere wrote: > On Fri, Oct 10, 2008 at 2:08 AM, Norman Rasmussen > <[email protected]> wrote: >> With the proposed requirement of TLS encryption when connecting to a server, >> the plaintext requirement is only slightly relaxed -- you end up trusting >> the TLS layer to protect your password from attack. > > Which the rest of the world has agreed is a much safer assertion then > trusting server admins to keep the passwords safe. (see reddit for > example of leaking passwords). Frankly it's just a bad idea to store > the passwords in plain-text and the sooner that gets fixed not only in > the spec but as an understanding within the community the better. How does the spec (I assume you mean RFC 3920) require that you store plaintext passwords? Also, I'm curious to find out how a large IM service would migrate from one XMPP server codebase to another if the passwords are hashed (as for instance we did at jabber.org in February 2006 when we switched from jabberd 1.x to ejabberd 1.x). I don't like storing plaintext passwords, so I'd like to learn what the real-world alternatives are (short of certificate login). Peter -- Peter Saint-Andre https://stpeter.im/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________