Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-12 Thread Peter Saint-Andre
On 9/7/11 8:51 PM, Peter Saint-Andre wrote: On 9/7/11 2:33 PM, Joe Hildebrand wrote: On 9/5/11 6:39 AM, Dave Cridland d...@cridland.net wrote: Of course, it may be simplest just to bite the bullet and switch hash algorithm - or even change the 'hash' attribute name - because then it'll get

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-12 Thread Andreas Monitzer
On Montag, 12. September 2011 at 23:22, Peter Saint-Andre wrote: One of the major problems with the current approach is that there's no hard border between identities and features, and between features and extensions. As a result, malicious software can define certain clever identities and

[Standards] Proposal for XEP-0302

2011-09-12 Thread Andreas Monitzer
Hi, I'd like to propose XEP-0084 User Avatar to be included for the advanced client in the 2012 compliance suite. The vcard-temp-based avatars are a huge legacy that I'd be very delighted to see gone. User Avatar is already supported in all libpurple-based clients and I believe in others as