Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Joe Hildebrand
On 9/14/11 4:31 PM, "Waqas Hussain" wrote: > An entity which understood double verify would have the option to > either be vulnerable to poisoning, or participate in IQ floods. It's > this that I'm against. Presumably, the new XEP would recommend that you negatively cache in the case that it re

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Matthew A. Miller
On Sep 14, 2011, at 16:31, Waqas Hussain wrote: > On Thu, Sep 15, 2011 at 1:37 AM, Matthew A. Miller > wrote: >> >> On Sep 14, 2011, at 13:40, Waqas Hussain wrote: >> >>> >>> So.. which caps is included in presence? The current exploitable one? >>> Then this doesn't help with preventing poison

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Waqas Hussain
On Thu, Sep 15, 2011 at 1:37 AM, Matthew A. Miller wrote: > > On Sep 14, 2011, at 13:40, Waqas Hussain wrote: > >> >> So.. which caps is included in presence? The current exploitable one? >> Then this doesn't help with preventing poisoning, does it? >> > > the caps hash would be as it is today.  S

Re: [Standards] MSN does XMPP

2011-09-14 Thread Mark Rejhon
Agreed... I would like Microsoft to pass through XEP-0301 (In-Band Real-Time Text). I know that someone from Microsoft's team contacted me inquiring about this; an steps from Microsoft should be encouraged. Standardized tests such as Acid made Microsoft Internet Explorer 9 much more compliant, so

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 3:52 PM, Peter Saint-Andre wrote: > On 9/14/11 3:14 PM, David Ammouial wrote: >> 14/09/2011, Justin: >>> - login requires using a special SASL mechanism >>> "X-MESSENGER-OAUTH2". - JIDs are {identifier}@messenger.live.com, >>> where {identifier} comes from the OAuth access token. >> >>

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 3:53 PM, Peter Saint-Andre wrote: > On 9/14/11 1:49 PM, Peter Saint-Andre wrote: >> On 9/14/11 1:12 PM, Nicolas Vérité wrote: >>> On Wed, Sep 14, 2011 at 20:52, Peter Saint-Andre wrote: On 9/14/11 12:49 PM, Dave Cridland wrote: > Running some > interop tests Perha

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 1:49 PM, Peter Saint-Andre wrote: > On 9/14/11 1:12 PM, Nicolas Vérité wrote: >> On Wed, Sep 14, 2011 at 20:52, Peter Saint-Andre wrote: >>> On 9/14/11 12:49 PM, Dave Cridland wrote: Running some interop tests >>> >>> Perhaps it's time for another online interop test? >> >> Pe

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 3:14 PM, David Ammouial wrote: > 14/09/2011, Justin: >> - login requires using a special SASL mechanism >> "X-MESSENGER-OAUTH2". - JIDs are {identifier}@messenger.live.com, >> where {identifier} comes from the OAuth access token. > > Could it be linked to this old, deferred specificati

Re: [Standards] MSN does XMPP

2011-09-14 Thread David Ammouial
14/09/2011, Justin: > - login requires using a special SASL mechanism > "X-MESSENGER-OAUTH2". > - JIDs are {identifier}@messenger.live.com, where {identifier} > comes from the OAuth access token. Could it be linked to this old, deferred specification? http://xmpp.org/extensions/xep-0235.html

Re: [Standards] MSN does XMPP

2011-09-14 Thread Justin Karneges
On Wednesday, September 14, 2011 01:02:13 PM Tobias Markmann wrote: > On Wed, Sep 14, 2011 at 22:00, Justin Karneges > > wrote: > > - login requires using a special SASL mechanism "X-MESSENGER-OAUTH2". > > Is that by any chance > http://tools.ietf.org/html/draft-mills-kitten-sasl-oauth-03 ? I

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Matthew A. Miller
On Sep 14, 2011, at 13:40, Waqas Hussain wrote: > On Wed, Sep 14, 2011 at 12:04 AM, Matthew A. Miller > wrote: >> >> On Sep 13, 2011, at 12:18, Matthew A. Miller wrote: >> >> >>> I've been thinking of something that might be a less-awful compromise. >>> I'll post to this list about it soon

Re: [Standards] MSN does XMPP

2011-09-14 Thread Tobias Markmann
On Wed, Sep 14, 2011 at 22:00, Justin Karneges wrote: >  - login requires using a special SASL mechanism "X-MESSENGER-OAUTH2". > Is that by any chance http://tools.ietf.org/html/draft-mills-kitten-sasl-oauth-03 ?

Re: [Standards] MSN does XMPP

2011-09-14 Thread Justin Karneges
On Wednesday, September 14, 2011 12:25:52 PM Justin Karneges wrote: > On Wednesday, September 14, 2011 10:43:38 AM Nicolas Vérité wrote: > > Thanks for those of you who twitted it: > > http://www.liveside.net/2011/09/14/messenger-connect-is-now-live-connect- > > ne w-apis-for-skydrive-and-hotmail-c

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 1:12 PM, Nicolas Vérité wrote: > On Wed, Sep 14, 2011 at 20:52, Peter Saint-Andre wrote: >> On 9/14/11 12:49 PM, Dave Cridland wrote: >>> Running some >>> interop tests >> >> Perhaps it's time for another online interop test? > > Perhaps it's time to go further than these interop tests

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Waqas Hussain
On Wed, Sep 14, 2011 at 12:04 AM, Matthew A. Miller wrote: > > On Sep 13, 2011, at 12:18, Matthew A. Miller wrote: > > >> I've been thinking of something that might be a less-awful compromise.  I'll >> post to this list about it soon for us all to mock and ridicule (-: >> > > So, the less-awful c

Re: [Standards] Addressing Security Concerns in XEP-0115 Entity Capabilities

2011-09-14 Thread Waqas Hussain
On Tue, Sep 13, 2011 at 2:22 AM, Peter Saint-Andre wrote: > On 9/7/11 8:51 PM, Peter Saint-Andre wrote: >> On 9/7/11 2:33 PM, Joe Hildebrand wrote: >>> On 9/5/11 6:39 AM, "Dave Cridland" wrote: >>> Of course, it may be simplest just to bite the bullet and switch hash algorithm - or even

Re: [Standards] MSN does XMPP

2011-09-14 Thread Justin Karneges
On Wednesday, September 14, 2011 10:43:38 AM Nicolas Vérité wrote: > Thanks for those of you who twitted it: > http://www.liveside.net/2011/09/14/messenger-connect-is-now-live-connect-ne > w-apis-for-skydrive-and-hotmail-calendar/ XMPP Interface : You can > integrate Messenger into your Web-based,

Re: [Standards] MSN does XMPP

2011-09-14 Thread Nicolas Vérité
On Wed, Sep 14, 2011 at 20:52, Peter Saint-Andre wrote: > On 9/14/11 12:49 PM, Dave Cridland wrote: >> Running some >> interop tests > > Perhaps it's time for another online interop test? Perhaps it's time to go further than these interop tests? -- Nicolas Vérité (Nÿco) mailto:nicolas.ver...@gma

Re: [Standards] MSN does XMPP

2011-09-14 Thread Peter Saint-Andre
On 9/14/11 12:49 PM, Dave Cridland wrote: > On Wed Sep 14 18:43:38 2011, Nicolas Vérité wrote: >> It's Microsoft! Quite a sign... but... >> >> Now, what we may see is cheating on the protocol, interop risks. > > I'd rather assume that any bugs in the implementation are just that - > unintentional

Re: [Standards] MSN does XMPP

2011-09-14 Thread Dave Cridland
On Wed Sep 14 18:43:38 2011, Nicolas Vérité wrote: It's Microsoft! Quite a sign... but... Now, what we may see is cheating on the protocol, interop risks. I'd rather assume that any bugs in the implementation are just that - unintentional errors - until we hear otherwise. I hope they do ha

[Standards] MSN does XMPP

2011-09-14 Thread Nicolas Vérité
Hi, Thanks for those of you who twitted it: http://www.liveside.net/2011/09/14/messenger-connect-is-now-live-connect-new-apis-for-skydrive-and-hotmail-calendar/ XMPP Interface : You can integrate Messenger into your Web-based, desktop, or mobile instant messaging products by connecting to our XMPP