On 07.03.2017 12:31, Jonas Wielicki wrote:
> On Dienstag, 28. Februar 2017 16:27:59 CET XMPP Extensions Editor wrote:
>> This message constitutes notice of a Last Call for comments on XEP-0186
>> (Invisible Command).
>>
>> 4. Do you have any security concerns related to this specification? 
> 
> The Security Considerations section is very vague. While I can imagine some 
> of 
> the scenarios hinted at, I think that mentioning some cases would not hurt. 
> Examples I am currently thinking of are disco#* (or all IQs to the client in 
> general) and Message Delivery Receipts. I’m sure there is more.

A presence leak is a generic XMPP security consideration which should be
handled in one canonical place, possibly put in one of the RFCs, and not
in one of the 300+ XEPs. Then XEP-0186, and other relevant XEPs like the
Message Delivery Receipts one, could point to that canonical place.

Unfortunately I only found RFC 6120 § 13.10.2 which discusses the
service's responsibility. Maybe it is worth to write an extra XEP for
this until 6120bis arrives?

- Florian

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to