Re: Jabber in the company

Peter Saint-Andre <[email protected]>
Newsgroups gmane.network.jabber.user
Message-ID <[email protected]>
On 4/16/10 12:20 AM, Torsten Bronger wrote:
> Hallöchen!
> 
> Peter Saint-Andre writes:
> 
>> On 4/13/10 10:12 AM, Torsten Bronger wrote:
>>
>>> [...]
>>>
>>> Now I plan to suggest an openfire officially here, ideally with
>>> S2S communication.  How should I do that?  Does anybody here have
>>> experiences?  In particular, the IT department will tell me that
>>> they have security concerns.  Is this valid?  Are there studies
>>> about virus infections through Jabber in companies?  What are
>>> counter-measures?
>>
>> What are the exact security concerns? XMPP uses TLS to encrypt
>> connections, SASL for strong authentication, has a diverse
>> ecosystem of clients, no known viruses, etc. It's much safer than
>> email. :)
> 
> I think malware sent by XMPP is the most important concern.  Of
> course, your answer is not suprising for me.  But our IT bans ICQ
> and MSN due to malware intrusion.  I think that even for ICQ and MSN
> this is a lame argument.  Anyway, "no known viruses" is a clear
> quotable statement, thank you.

First, you can deploy XMPP inside your company without opening up
server-to-server communication with any other domains (intranet
deployment). You can't do that with ICQ or MSN. If the only users are
people inside your company, then the malware threat becomes much less
serious (and I assume that you have solutions to people who abuse
internal networks -- it's called getting fired).

Second, XMPP has a very diverse client ecosystem, which makes it much
harder to attack XMPP systems than it is to attack something like MSN
(which has one primary client). Even if someone came up with an attack
against XMPP Client #1, that attack probably would not work against XMPP
Client #2.

The main problem you might theoretically face is file transfer. If
someone could write a worm that infected a particular XMPP client, that
client could spread itself by sending file transfers to all of your
buddies (although they would still need to explicitly accept the file
transfer). We have never had any such malware on the XMPP network since
1999, but it is possible that someone could write such a worm. But IMHO
there are much easier targets to attack even in the IM world (AOL, ICQ,
MSN, etc.), so I don't lose any sleep over this one. But if you are
really paranoid you could deploy a branded XMPP client that did not have
support for file transfer.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/

_______________________________________________
This is JUser -- a mailing list for end users
of Jabber clients.

Don't like email? Try the forum:
http://www.jabberforum.org/forumdisplay.php?f=21

To unsubscribe, send email to
[email protected]
or go to the following web
page, scroll all the way down,
and type in your email address:

http://mail.jabber.org/mailman/listinfo/juser
_______________________________________________
smime.p7s (application/pkcs7-signature, 6.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.