Re: [Standards] XEP-0359: Unique and Stable Stanza IDs, PR#1272 Add security consideration and

2023-02-21 Thread Thilo Molitor
+1 for an informational xep detailing how to reference messages in various scenarios (muc, 1:1 etc.). Am Dienstag, 21. Februar 2023, 21:17:23 CET schrieb Marvin W: > Hi, > > This is feedback for the latest PR to XEP-0359. > > > The value of origin-id is spoofable and hence MUST not be used

Re: [Standards] XEP-0359: Unique and Stable Stanza IDs, PR#1272 Add security consideration and

2023-02-21 Thread Marvin W
Hi, This is feedback for the latest PR to XEP-0359. > The value of origin-id is spoofable and hence MUST not be used when referencing other stanzas. - This doesn't explain at all what "spoofable" means. - origin-id's are supposed to be unique only within the scope of the origin. In

Re: [Standards] XEP-0424: Message Retraction - Remove Fastening

2023-02-21 Thread Marvin W
I think we came up with the common understanding that to reference a previous message in a conversation, we use - the origin-id or message id in direct chats - the MUC service's stanza-id in MUCs + some kind of method (e.g. presence tracking, occupant-id) to have certainty that the sender is the