Re: Plaintext passwords
Peter Saint-Andre <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
Simon Friedberger wrote: >> c) The DIGEST-MD5 approach: >> Pro: The password is not sent over the wire. The password can be >> stored as a salted hash (salt is user/realm) in the database (can't use >> rainbow tables to reverse hash). >> Con: If you decide that MD5 isn't cutting it, and you want to use >> SomeotherHashAlgorithm instead, then you need to ask the user for the >> plaintext password (or a new username/realm/password hash). > > While I do like this approach you don't seem to be such a big fan > yourself or am I mistaken? > Also, maybe Peter can tell us more about the abandonment by the IETF. As I understand it, a big part of the problem with DIGEST-MD5 as a SASL mechanism was the inconsistent documentation and implementation. This led to many interoperability problems -- so much so that people decided to abandon it and work on something new, rather try to move forward with DIGEST-MD5. But I have not studied the details, so there may be more substantive reasons behind the deprecation. Peter -- Peter Saint-Andre https://stpeter.im/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________