[Standards] Re: LAST CALL: XEP-0458 (Community Code of Conduct)

2023-10-31 Thread Guus der Kinderen
Hello, Thank you for the work that has gone into this. To me, the document is clearly worded. I would appreciate elaboration on the sentence "Humour is not a mitigating factor here" in section 2.3. An additional suggestions is to add a reminder that we do not all share a common cultural backgroun

[Standards] Re: NEW: XEP-0474 (SASL SCRAM Downgrade Protection)

2023-10-31 Thread Ruslan N. Marchenko
Am Samstag, dem 28.10.2023 um 14:40 +0100 schrieb Matthew Wild: > > So, SSDP "only" allows the client to detect the difference between > two cases: > > 1) The real server advertises new channel binding methods the client > does not understand > 2) An MITM is trying to trick the client into authen

[Standards] LAST CALL: XEP-0458 (Community Code of Conduct)

2023-10-31 Thread Peter Saint-Andre
This message constitutes notice of a Last Call for comments on XEP-0458, a Procedural XEP that the XSF Board of Directors is considering for advancement to a status of Active. Title: Community Code of Conduct Abstract: This document describes the XMPP Standard Foundation's Code of Conduct.

[Standards] Re: NEW: XEP-0474 (SASL SCRAM Downgrade Protection)

2023-10-31 Thread Thilo Molitor
Hi Matthew, the following is written under the premise that the client does not support SASL PLAIN. SSDP is a replacement for pinning, that solves two main shortcomings when doing pinning (either for channel-binding types or for SASL mechanisms), while still being at least as secure as pinning