Re: Plaintext passwords

"Norman Rasmussen" <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On Fri, Oct 10, 2008 at 8:40 PM, Simon Friedberger
<[email protected]<simon%[email protected]>
> wrote:

> Sorry, I don't see the weakness in asking users to pick new passwords.
>

snip


> Or you could just write them a message saying "For security purposes
> please enter your password again." and have the new hash computed by the
> client and sent to the server which in turn may store it. (Though that's
> just something I came up with right now so it may be inherently flawed.)
>

If the server (you checked it was the server's jid right?) sent you an im
with a link to a web-page with this type of request, would you do it?  How
would you check that the page's url was valid?  If I told you you had to
download a special program to do it, would you do it?

Asking the user to pick a new password is hard, because it's almost
impossible to make sure that they're only ever going to send that password
into your service - and not into the waiting hands of some spammer
somewhere.

-- 
- Norman Rasmussen
- Email: [email protected]
- Home page: http://norman.rasmussen.co.za/

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.