Re: Plaintext passwords
Peter Saint-Andre <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
anders conbere wrote: > On Fri, Oct 10, 2008 at 12:39 PM, Peter Saint-Andre <[email protected]> wrote: >> anders conbere wrote: >>> On Fri, Oct 10, 2008 at 2:08 AM, Norman Rasmussen >>> <[email protected]> wrote: >>>> With the proposed requirement of TLS encryption when connecting to a server, >>>> the plaintext requirement is only slightly relaxed -- you end up trusting >>>> the TLS layer to protect your password from attack. >>> Which the rest of the world has agreed is a much safer assertion then >>> trusting server admins to keep the passwords safe. (see reddit for >>> example of leaking passwords). Frankly it's just a bad idea to store >>> the passwords in plain-text and the sooner that gets fixed not only in >>> the spec but as an understanding within the community the better. >> How does the spec (I assume you mean RFC 3920) require that you store >> plaintext passwords? > > I'm not sure it does, but it's a common argument on this list that > "we're stuck with plain text password because of the requirement to > support Digest Auth" Well, Digest-MD5 is has been deprecated at the IETF (without a replacement!) so it is being removed from rfc3920bis to be replaced by TLS+SASL-PLAIN. Peter -- Peter Saint-Andre https://stpeter.im/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________