Re: Plaintext passwords

Peter Saint-Andre <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
Norman Rasmussen wrote:

> My personal server uses pam for authentication, so users _have_ to use
> plaintext authentication via TLS, and if they want to change their
> passwords, they have to use passwd via ssh.  It's pretty secure, but
> hard to scale for services like jabber.org

Er, yeah, that's not going to work at jabber.org -- we have 300k+ users.
Because we don't have email addresses on file for our users, we don't
have an automated way for people to request lost passwords (users can
change their passwords via XEP-0077, but that doesn't work if you have
forgotten your password). Currently when someone forgets their password,
they contact me directly and I manually change their password. That
approach doesn't scale, but I typically receive only one request a day
so it's not really a big deal. However, this forces us to store
plaintext passwords. Of course, the beauty of Jabber is that if you
don't like this policy, you can always run your own server. :)

Peter

-- 
Peter Saint-Andre
https://stpeter.im/

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.