eyecu-im / eyecu-qt

eyeCU XMPP client (mirror)
GNU General Public License v3.0
5 stars 2 forks source link

SCRAM-SHA-1-PLUS + SCRAM-SHA-256-PLUS + SCRAM-SHA-512-PLUS + SCRAM-SHA3-512(-PLUS) supports #10

Open Neustradamus opened 7 months ago

Neustradamus commented 7 months ago

After:

Can you add supports of :

A "big" list has been done in last link of this ticket.


SCRAM-SHA-1(-PLUS):

SCRAM-SHA-256(-PLUS):

SCRAM-SHA-512(-PLUS):

SCRAM-SHA3-512(-PLUS):

SCRAM BIS: Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms:

-PLUS variants:

IMAP:

LDAP:

HTTP:

JMAP:

2FA:

IANA:

Linked to:

Neustradamus commented 7 months ago

Dear @eyecu-im team, @Yagiza, @xnamed,

It is possible to comment this important Qt ticket about Channel Binding?

It is to needed to have support of SCRAM-SHA-*-PLUS variants.

Recently, we have seen the jabber.ru MITM:

Thanks in advance.

Yagiza commented 7 months ago

Hello! Yes, I'll try. 11.11.2023, 00:54, "Neustradamus" @.>: Dear @eyecu-im team, @Yagiza, @xnamed,It is possible to comment this important Qt ticket about Channel Binding?https://bugreports.qt.io/browse/QTBUG-77783It is to needed to have support of SCRAM-SHA--PLUS variants.Recently, we have seen the jabber.ru MITM:https://notes.valdikss.org.ru/jabber.ru-mitm/https://snikket.org/blog/on-the-jabber-ru-mitm/https://www.devever.net/~hl/xmpp-incidenthttps://blog.jmp.chat/b/certwatchThanks in advance.—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you were mentioned.Message ID: **@.***>

Neustradamus commented 5 months ago

Dear @eyecu-im team members,

I wish you a Happy New Year 2024!

After some comments, an email sent to security@qt.io, there is an important comment about my original ticket about Channel Binding and Qt, I think that you can do an answer here? You are impacted...

Thanks in advance.