Ask HN:哪些 Jabber 客户端不仅支持 SCRAM+ 和 XEP-0474
1 分•作者: Bender•2 个月前
与此讨论串 [1] 相关,该讨论串指出 Jabber 客户端不仅能在中间人攻击(MitM)时,使用服务器上不存在但有效的证书进行篡改,并且客户端会拒绝此替代的有效证书,还会向用户发出 MitM 警报。XEP-0474 SASL SCRAM 降级保护 <i>(实验性)</i> [2] Claude 似乎不了解,我也找不到任何澄清文档,只有很多未解决的问题。
目的是撰写一篇关于端到端加密(E2EE)的文章,但我想推荐一些客户端,它们能在中间人攻击篡改时发出警报,并且用户无法轻易忽略。<i>即,不会轻易点击忽略警告</i>
[1] - https://news.ycombinator.com/item?id=37955264
[2] - https://xmpp.org/extensions/xep-0474.html
查看原文
Related to this thread [1] which Jabber clients not only detect MitM tampering when a valid cert is used in the middle but is not the cert on the server, meaning an entity obtained a certificate, used it to MitM the connection and the client not only rejects this alternate valid certificate but also alerts the user to the MitM. XEP-0474 SASL SCRAM Downgrade Protection <i>(Experimental)</i> [2] Claude does not seem to know and I can't find any clarifying documentation, just lots of open issues.<p>The purpose is for writing an article on E2EE but I want to suggest clients that will alert on MitM tampering in a manor the person using the client can not accidentally ignore it. <i>i.e. just click through a warning</i><p>[1] - https://news.ycombinator.com/item?id=37955264<p>[2] - https://xmpp.org/extensions/xep-0474.html