Re: Plaintext passwords
"Norman Rasmussen" <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Oct 10, 2008 at 8:40 PM, Simon Friedberger <[email protected]<simon%[email protected]> > wrote: > Sorry, I don't see the weakness in asking users to pick new passwords. > snip > Or you could just write them a message saying "For security purposes > please enter your password again." and have the new hash computed by the > client and sent to the server which in turn may store it. (Though that's > just something I came up with right now so it may be inherently flawed.) > If the server (you checked it was the server's jid right?) sent you an im with a link to a web-page with this type of request, would you do it? How would you check that the page's url was valid? If I told you you had to download a special program to do it, would you do it? Asking the user to pick a new password is hard, because it's almost impossible to make sure that they're only ever going to send that password into your service - and not into the waiting hands of some spammer somewhere. -- - Norman Rasmussen - Email: [email protected] - Home page: http://norman.rasmussen.co.za/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________