On 07.03.2017 12:31, Jonas Wielicki wrote: > On Dienstag, 28. Februar 2017 16:27:59 CET XMPP Extensions Editor wrote: >> This message constitutes notice of a Last Call for comments on XEP-0186 >> (Invisible Command). >> >> 4. Do you have any security concerns related to this specification? > > The Security Considerations section is very vague. While I can imagine some > of > the scenarios hinted at, I think that mentioning some cases would not hurt. > Examples I am currently thinking of are disco#* (or all IQs to the client in > general) and Message Delivery Receipts. I’m sure there is more.
A presence leak is a generic XMPP security consideration which should be handled in one canonical place, possibly put in one of the RFCs, and not in one of the 300+ XEPs. Then XEP-0186, and other relevant XEPs like the Message Delivery Receipts one, could point to that canonical place. Unfortunately I only found RFC 6120 § 13.10.2 which discusses the service's responsibility. Maybe it is worth to write an extra XEP for this until 6120bis arrives? - Florian
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
