On Tue, Aug 5, 2008 at 10:16 AM, Peter Saint-Andre <[EMAIL PROTECTED]> wrote: > Maciek Niedzielski wrote: >> >> Peter Saint-Andre wrote: >>> >>> Olivier Goffart wrote: >>>> >>>> It would be cool to add a way to specify a new jid, so the server could >>>> reply with a <gone/> error with the new Jid >>>> or even forward message to the new one. >>> >>> What prevents a malicious user from setting up an account, subscribing it >>> to every bot on the network, and then forwarding that traffic to some third >>> user? Sounds like a fun attack. :) >> >> >> http://www.xmpp.org/extensions/inbox/forwarding-request.html >> >> Written by you ;) > > Yeah, but the Council never approved it because of security concerns and > such... :/
I've heard a lot of talk about transparent forwarding floating around, and I simply can't think of any way without reasonable support for digitally signing stanza's to roll that out with out seriously endangering the xmpp ecosystem with spam. ~ Anders > > /psa > >
