Hi all,

As stated in xsf@ this is trivially MITM'able isn't it ? I can advertise your XID at my JID and then when anyone sends me a challenge I just send it to you and reply back with your response to me?

Signing just the nonce is clearly inadequate, I think signing the nonce + sender jid + responder jid (separated with something that can't be in any of the above, I think a null byte should do?) would work, and you wouldn't need to keep timestamp but if you do that should be concatenated+signed too.

Thanks,
moparisthebest


On June 30, 2026 11:00:34 AM EDT, Daniel Gultsch <daniel@gultsch.de> wrote:
Version 0.1.0 of XEP-0516 (XMPP Decentralized ID (XID)) has been
released.

Abstract:
XMPP Decentralized ID (XID) is a DNS independent XMPP entity
identifier. This specification describes how to generate, use, and
handle them.

Changelog:
Accepted as Experimental by council vote (XEP Editor (dg))

URL: https://xmpp.org/extensions/xep-0516.html

Note: The information in the XEP list at https://xmpp.org/extensions/
is updated by a separate automated process and may be stale at the
time this email is sent. The XEP documents linked herein are up-to-
date.
Standards mailing list -- standards@xmpp.org
To unsubscribe send an email to standards-leave@xmpp.org