Ask HN:哪些 Jabber 客户端不仅支持 SCRAM+ 和 XEP-0474

1 分•作者: Bender•2 个月前
与此讨论串 [1] 相关,该讨论串指出 Jabber 客户端不仅能在中间人攻击(MitM)时,使用服务器上不存在但有效的证书进行篡改,并且客户端会拒绝此替代的有效证书,还会向用户发出 MitM 警报。XEP-0474 SASL SCRAM 降级保护 <i>(实验性)</i> [2] Claude 似乎不了解,我也找不到任何澄清文档,只有很多未解决的问题。 目的是撰写一篇关于端到端加密(E2EE)的文章,但我想推荐一些客户端,它们能在中间人攻击篡改时发出警报,并且用户无法轻易忽略。<i>即,不会轻易点击忽略警告</i> [1] - https://news.ycombinator.com/item?id=37955264 [2] - https://xmpp.org/extensions/xep-0474.html
查看原文
Related to this thread [1] which Jabber clients not only detect MitM tampering when a valid cert is used in the middle but is not the cert on the server, meaning an entity obtained a certificate, used it to MitM the connection and the client not only rejects this alternate valid certificate but also alerts the user to the MitM. XEP-0474 SASL SCRAM Downgrade Protection <i>(Experimental)</i> [2] Claude does not seem to know and I can&#x27;t find any clarifying documentation, just lots of open issues.<p>The purpose is for writing an article on E2EE but I want to suggest clients that will alert on MitM tampering in a manor the person using the client can not accidentally ignore it. <i>i.e. just click through a warning</i><p>[1] - https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37955264<p>[2] - https:&#x2F;&#x2F;xmpp.org&#x2F;extensions&#x2F;xep-0474.html