Re: [Standards] Proposed XMPP Extension: SASL SCRAM Downgrade Protection

2022-10-17 Thread Peter Saint-Andre
On 10/17/22 5:27 PM, Thilo Molitor wrote: Thanks for your feedback Dave! Am Montag, 17. Oktober 2022, 15:36:56 CEST schrieb Dave Cridland: Any attacker able to manipulate the data coming from the server such that the client sees a restricted set of TLS channel bindings can also manipulate the d

Re: [Standards] Proposed XMPP Extension: SASL SCRAM Downgrade Protection

2022-10-17 Thread Thilo Molitor
Thanks for your feedback Dave! Am Montag, 17. Oktober 2022, 15:36:56 CEST schrieb Dave Cridland: > Any attacker able to manipulate the data coming from the server such that > the client sees a restricted set of TLS channel bindings can also > manipulate the data coming from the server such that th

Re: [Standards] Proposed XMPP Extension: SASL SCRAM Downgrade Protection

2022-10-17 Thread Dave Cridland
On Wed, 12 Oct 2022 at 17:17, Jonas Schäfer wrote: > Title: SASL SCRAM Downgrade Protection > URL: https://xmpp.org/extensions/inbox/xep-downgrade-prevention.html Any attacker able to manipulate the data coming from the server such that the client sees a restricted set of TLS channel bindings c