Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Philipp Hancke
Am 11.08.21 um 23:49 schrieb Peter Saint-Andre: On 8/11/21 3:35 PM, Kim Alvefur wrote: On Wed, Aug 11, 2021 at 02:25:56PM -0600, Peter Saint-Andre wrote: Too bad we didn't stick to our guns in 2003 and insist on two ports instead of one, but STARTTLS was the recommended approach back then...

Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Peter Saint-Andre
On 8/11/21 3:35 PM, Kim Alvefur wrote: > On Wed, Aug 11, 2021 at 02:25:56PM -0600, Peter Saint-Andre wrote: >> Too bad we didn't stick to our guns in 2003 and insist on two ports >> instead of one, but STARTTLS was the recommended approach back then... > > We were always at war with STARTTLS? We

Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Kim Alvefur
On Wed, Aug 11, 2021 at 02:25:56PM -0600, Peter Saint-Andre wrote: Too bad we didn't stick to our guns in 2003 and insist on two ports instead of one, but STARTTLS was the recommended approach back then... We were always at war with STARTTLS? -- Zash signature.asc Description: PGP signature

Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Sam Whited
In my experience it's widely supported these days. Out of the 119 providers on the jabber.at server list 74 of them (62%) have xmpps records (though I did not test whether these resulted in a successful connection with a reasonable TLS configuration). I also don't know if clients prioritize these

Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Peter Saint-Andre
Too bad we didn't stick to our guns in 2003 and insist on two ports instead of one, but STARTTLS was the recommended approach back then... On 8/11/21 2:13 PM, Philipp Hancke wrote: > tl;dr: its a mess. What is the deployment state of xep-0368? > > Am 11.08.21 um 19:08 schrieb Peter Saint-Andre:

Re: [Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Philipp Hancke
tl;dr: its a mess. What is the deployment state of xep-0368? Am 11.08.21 um 19:08 schrieb Peter Saint-Andre: Perhaps of interest here... Forwarded Message Subject: [Uta] STARTTLS vulnerabilities Date: Wed, 11 Aug 2021 17:42:40 +0200 From: Hanno Böck To: u...@ietf.org Hi,

[Standards] Fwd: [Uta] STARTTLS vulnerabilities

2021-08-11 Thread Peter Saint-Andre
Perhaps of interest here... Forwarded Message Subject: [Uta] STARTTLS vulnerabilities Date: Wed, 11 Aug 2021 17:42:40 +0200 From: Hanno Böck To: u...@ietf.org Hi, I wanted to share some research we have done on vulnerabilities in STARTTLS implementations:

[Standards] Council Minutes 2021-08-11

2021-08-11 Thread Jonas Schäfer
https://logs.xmpp.org/council/2021-08-11#2021-08-11-9c0056346fa591e6 1) Roll Call Emerging from a horrifying reading, Jonas opens the meeting a tad late. Present: Jonas, Zash, Daniel, Georg 2) Agenda Bashing None. 3) Editor’s Update - Pubsub Caching Hints have been accepted as New as per

Re: [Standards] Proposed XMPP Extension: Disco Feature Attachment

2021-08-11 Thread Jonas Schäfer
Hi goffi, Thanks for proposing this. The council has today vetoed the advancement for this ProtoXEP to Experimental, but I'd like to give you some feedback because I think the problem you're trying to address is real. The bottom of this email contains two recommendations from me which may