[Standards] Proposal for XEP-0302

2011-09-12 Thread Andreas Monitzer
Hi, I'd like to propose XEP-0084 User Avatar to be included for the advanced client in the 2012 compliance suite. The vcard-temp-based avatars are a huge legacy that I'd be very delighted to see gone. User Avatar is already supported in all libpurple-based clients and I believe in others as w

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-12 Thread Andreas Monitzer
On Montag, 12. September 2011 at 23:22, Peter Saint-Andre wrote: > One of the major problems with the current approach is that there's no > hard border between identities and features, and between features and > extensions. As a result, malicious software can define certain clever > identities and

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-12 Thread Peter Saint-Andre
On 9/7/11 8:51 PM, Peter Saint-Andre wrote: > On 9/7/11 2:33 PM, Joe Hildebrand wrote: >> On 9/5/11 6:39 AM, "Dave Cridland" wrote: >> >>> Of course, it may be simplest just to bite the bullet and switch hash >>> algorithm - or even change the 'hash' attribute name - because then >>> it'll get tre