Re: Plaintext passwords

"anders conbere" <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On Fri, Oct 10, 2008 at 2:09 PM, Simon Friedberger
<[email protected]> wrote:
>
> Phew.
> I just read through the original "[jadmin] jabberd14 'crypt' password
> storage in postgressql" thread.
>
> Very interesting indeed.
> The main point seems to be:
> We cannot protect users from mitm when storing the password as a hash
> only.
>
> Let me try to write a summary:
>
> a) The passwd approach:
>        Pro: The server does not store the passwords.
>        Con: The password has to be sent over the wire.
> b) The CRAM-MD5 approach:
>        Pro: The password is not sent over the wire.
>        Con: The server has to store the password.

I'm not convinced these are the only two options. There are certainly
authorization protocols in which the password only exists to create a
hash, and neither side has the unencryted password stored.

~ Anders

>
> Simple, isn't it? :)
>
> Now let's look at what might happen:
>
> I. The jabber server is compromised:
>        Either way the attacker gets everything.
>        The not-so-subtle difference is:
>        Using case b) The attacker immediately has access to the users password.
>        He may use the password to access other services where the user chose the same password.
>        While in case a) the attacker still has to:
>                1. successfully mount an offline attack on the hash.
>                2. impersonate the server to get the password when the
>                user logs on.
>
> II. MITM:
>        Assuming a secured line the attacker has to impersonate the
>        server without knowing the appropriate private key and the user
>        is prompted with a false certificate.
>        The user accepts that certificate.
>        In case a) the attacker immediately has access to the users
>        password. In case b) the attacker can only listen in on and
>        alter the users chatdata.
>
> Still pretty simple but which choice is to prefer?
>
> In both situations the users jabber account is compromised and it seems
> reasonable to examine _further_ damage. Consider the security unaware
> user who made the mistake of using the same password for multiple
> services.
>
> I then advocate a) is the better choice because:
>
> Case II. is imho difficult for the attacker because
> it
> - requires the attacker to be able intercept and alter the users traffic
> - requires the user to accept a false certificate
> while Case I. can occur if simply
> - an admin account is compromised
> - a local user escalates his privileges
> but _also_ if only the password database is compromised.
>
> Now maybe somebody would like to add something, change something. Feel
> free!
>
> At least I think that it should be obvious that this is a design choice
> depending on the setup and it should be configurable. The recurring and
> extensive discussion seems to prove that point.
>
> Ciao
>        Simon
> _______________________________________________
> JAdmin mailing list
> FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
> Forum: http://www.jabberforum.org/forumdisplay.php?f=19
> Info: http://mail.jabber.org/mailman/listinfo/jadmin
> Unsubscribe: [email protected]
> _______________________________________________
>
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.