Hi all,
As stated in xsf@ this is trivially MITM'able isn't it ? I can advertise your XID
at my JID and then when anyone sends me a challenge I just send it to you and reply back
with your response to me?
Signing just the nonce is clearly inadequate, I think signing the nonce + sender jid +
responder jid (separated with something that can't be in any of the above, I think a
null byte should do?) would work, and you wouldn't need to keep timestamp but if you
do that should be concatenated+signed too.
Thanks,
moparisthebest
On June 30, 2026 11:00:34 AM EDT, Daniel Gultsch <daniel(a)gultsch.de> wrote:
Version 0.1.0 of XEP-0516 (XMPP Decentralized ID (XID))
has been
released.
Abstract:
XMPP Decentralized ID (XID) is a DNS independent XMPP entity
identifier. This specification describes how to generate, use, and
handle them.
Changelog:
Accepted as Experimental by council vote (XEP Editor (dg))
URL:
https://xmpp.org/extensions/xep-0516.html
Note: The information in the XEP list at
https://xmpp.org/extensions/
is updated by a separate automated process and may be stale at the
time this email is sent. The XEP documents linked herein are up-to-
date.
_______________________________________________
Standards mailing list -- standards(a)xmpp.org
To unsubscribe send an email to standards-leave(a)xmpp.org