Re: [Standards] XEP-0198 and SASL-Anonymous

2013-01-25 Thread Matt Miller
On Jan 25, 2013, at 7:08 AM, Winfried Tilanus wrote: > Hi, > > And now we are talking about XEP-0198, I think the security > considerations should take some more situations in account for the > session hijacking protection. When properly and securely authenticated, > the authentication is enoug

[Standards] XEP-0198 and SASL-Anonymous

2013-01-25 Thread Winfried Tilanus
Hi, And now we are talking about XEP-0198, I think the security considerations should take some more situations in account for the session hijacking protection. When properly and securely authenticated, the authentication is enough protection against sesion hijacking. But when using SASL-Anonymous