Re: Plaintext passwords
"anders conbere" <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Oct 10, 2008 at 12:39 PM, Peter Saint-Andre <[email protected]> wrote: > anders conbere wrote: >> On Fri, Oct 10, 2008 at 2:08 AM, Norman Rasmussen >> <[email protected]> wrote: >>> With the proposed requirement of TLS encryption when connecting to a server, >>> the plaintext requirement is only slightly relaxed -- you end up trusting >>> the TLS layer to protect your password from attack. >> >> Which the rest of the world has agreed is a much safer assertion then >> trusting server admins to keep the passwords safe. (see reddit for >> example of leaking passwords). Frankly it's just a bad idea to store >> the passwords in plain-text and the sooner that gets fixed not only in >> the spec but as an understanding within the community the better. > > How does the spec (I assume you mean RFC 3920) require that you store > plaintext passwords? I'm not sure it does, but it's a common argument on this list that "we're stuck with plain text password because of the requirement to support Digest Auth" ~ Anders > > Also, I'm curious to find out how a large IM service would migrate from > one XMPP server codebase to another if the passwords are hashed (as for > instance we did at jabber.org in February 2006 when we switched from > jabberd 1.x to ejabberd 1.x). > > I don't like storing plaintext passwords, so I'd like to learn what the > real-world alternatives are (short of certificate login). > > Peter > > -- > Peter Saint-Andre > https://stpeter.im/ > > _______________________________________________ > JAdmin mailing list > FAQ: http://www.jabber.org/discussion-lists/jadmin-faq > Forum: http://www.jabberforum.org/forumdisplay.php?f=19 > Info: http://mail.jabber.org/mailman/listinfo/jadmin > Unsubscribe: [email protected] > _______________________________________________ > _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________