Re: Plaintext passwords

Simon Friedberger <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
> c) The DIGEST-MD5 approach:
>        Pro: The password is not sent over the wire.  The password can be
> stored as a salted hash (salt is user/realm) in the database (can't use
> rainbow tables to reverse hash).
>        Con: If you decide that MD5 isn't cutting it, and you want to use
> SomeotherHashAlgorithm instead, then you need to ask the user for the
> plaintext password (or a new username/realm/password hash).

While I do like this approach you don't seem to be such a big fan
yourself or am I mistaken? 
Also, maybe Peter can tell us more about the abandonment by the IETF.

Apart from that I still think that my point why the admin should be
allowed to chose from a) and b) is still valid. Any opinions on that? 

Good night
	Simon
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.