Re: Plaintext passwords

Peter Saint-Andre <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
anders conbere wrote:
> On Fri, Oct 10, 2008 at 12:39 PM, Peter Saint-Andre <[email protected]> wrote:
>> anders conbere wrote:
>>> On Fri, Oct 10, 2008 at 2:08 AM, Norman Rasmussen
>>> <[email protected]> wrote:
>>>> With the proposed requirement of TLS encryption when connecting to a server,
>>>> the plaintext requirement is only slightly relaxed -- you end up trusting
>>>> the TLS layer to protect your password from attack.
>>> Which the rest of the world has agreed is a much safer assertion then
>>> trusting server admins to keep the passwords safe. (see reddit for
>>> example of leaking passwords). Frankly it's just a bad idea to store
>>> the passwords in plain-text and the sooner that gets fixed not only in
>>> the spec but as an understanding within the community the better.
>> How does the spec (I assume you mean RFC 3920) require that you store
>> plaintext passwords?
> 
> I'm not sure it does, but it's a common argument on this list that
> "we're stuck with plain text password because of the requirement to
> support Digest Auth"

Well, Digest-MD5 is has been deprecated at the IETF (without a
replacement!) so it is being removed from rfc3920bis to be replaced by
TLS+SASL-PLAIN.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.