Re: Plaintext passwords
Simon Friedberger <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
> c) The DIGEST-MD5 approach: > Pro: The password is not sent over the wire. The password can be > stored as a salted hash (salt is user/realm) in the database (can't use > rainbow tables to reverse hash). > Con: If you decide that MD5 isn't cutting it, and you want to use > SomeotherHashAlgorithm instead, then you need to ask the user for the > plaintext password (or a new username/realm/password hash). While I do like this approach you don't seem to be such a big fan yourself or am I mistaken? Also, maybe Peter can tell us more about the abandonment by the IETF. Apart from that I still think that my point why the admin should be allowed to chose from a) and b) is still valid. Any opinions on that? Good night Simon _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________