Re: Plaintext passwords

"anders conbere" <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On Fri, Oct 10, 2008 at 12:39 PM, Peter Saint-Andre <[email protected]> wrote:
> anders conbere wrote:
>> On Fri, Oct 10, 2008 at 2:08 AM, Norman Rasmussen
>> <[email protected]> wrote:
>>> With the proposed requirement of TLS encryption when connecting to a server,
>>> the plaintext requirement is only slightly relaxed -- you end up trusting
>>> the TLS layer to protect your password from attack.
>>
>> Which the rest of the world has agreed is a much safer assertion then
>> trusting server admins to keep the passwords safe. (see reddit for
>> example of leaking passwords). Frankly it's just a bad idea to store
>> the passwords in plain-text and the sooner that gets fixed not only in
>> the spec but as an understanding within the community the better.
>
> How does the spec (I assume you mean RFC 3920) require that you store
> plaintext passwords?

I'm not sure it does, but it's a common argument on this list that
"we're stuck with plain text password because of the requirement to
support Digest Auth"

~ Anders

>
> Also, I'm curious to find out how a large IM service would migrate from
> one XMPP server codebase to another if the passwords are hashed (as for
> instance we did at jabber.org in February 2006 when we switched from
> jabberd 1.x to ejabberd 1.x).
>
> I don't like storing plaintext passwords, so I'd like to learn what the
> real-world alternatives are (short of certificate login).
>
> Peter
>
> --
> Peter Saint-Andre
> https://stpeter.im/
>
> _______________________________________________
> JAdmin mailing list
> FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
> Forum: http://www.jabberforum.org/forumdisplay.php?f=19
> Info: http://mail.jabber.org/mailman/listinfo/jadmin
> Unsubscribe: [email protected]
> _______________________________________________
>
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.