Viewing profile — infosechandbook
infosechandbook
HN member- Joined
- Thu, Nov 04, 2021, 12:15 PM UTC
- HN karma
- 40
- Public activity
- 29 items
- HN profile
- View on Hacker News ↗
About infosechandbook
No profile information was provided.
Recent public activity
-
comment
Comment #29909971
> You can save XMPP account IDs in any mobile address book. ... while the rest of the XMPP account remains on the XMPP server, inaccessible. There is no benefit as you can also sto…
-
comment
Comment #29907116
Just one question as the rest was discussed numerous times before: > At least with XMPP, I can point the same client to some other server and potentially continue a conversation wi…
-
comment
Comment #29902816
You just wrote it is "silly" to compare XMPP with Signal while constantly doing it yourself. > Signal admins too can ship you an app Or I could just use my own Signal client since …
-
comment
Comment #29902690
Yes, Quicksy from the Conversations developer who bragged about copying main features of WhatsApp and Signal. Another one is Kontalk, https://www.kontalk.org/ . Both XMPP clients r…
-
comment
Comment #29902670
> I can link a raspberry pi anywhere in the world to my XMPP server with a few lines of Python and some libraries. Once again, "I, as a tech-savvy person, can operate my highly-cus…
-
comment
Comment #29888864
> The Signal protocol is neither an open (you cannot propose changes or extensions in an open process) nor has it been submitted to an standards body. Who defines "open standard" i…
-
comment
Comment #29888788
> Comparing Signal with XMPP is silly. Could you please add your statement to any other comments by XMPP proponents that state "XMPP is better than Signal because ..."? Plus, could…
-
comment
Comment #29887921
> If you start with an argument ..., it's strange that you don't apply same logic to Signal admins Where is this 1-to-1 comparison you demand in the OP's original article? Security…
-
comment
Comment #29877574
> claiming XMPP is either the best ... Unfortunately, this seems to be the starting point of most discussions on XMPP. Somebody claims that XMPP solves all problems, and is secure …
-
comment
Comment #29877420
> Signal operators can also inject messages to people. Did you check this, and can you demonstrate a server-side message injection so that the Signal clients display the injected m…
-
comment
Comment #29874403
> Have you read the joinjabber.org security FAQ i linked? Not in detail as the OP linked to another article. We commented on OP's other article, not on your joinjabber.org security…
-
comment
Comment #29874013
> How many of your contacts who use Signal used their real phone number? Most of them; however, there is no obligation to provide any personal data when registering a SIM card in m…
-
comment
Comment #29873889
> disclosed to the server admin Please read the article before and after these items. The first finding isn't about the server admin but about external parties such as law enforcem…
-
comment
Comment #29873796
Nobody claimed that they look the same. As mentioned in the linked article, the behavior upon receiving an injected message is client specific. In any way, the injected message is …
-
comment
Comment #29873719
> I already responded to your "admin in the middle" article here And we already responded here: https://news.ycombinator.com/item?id=29106376 , and here: https://infosec-handbook.e…
-
comment
Comment #29873552
> Anyway the problem of Signal is that you have to use your phone number and a phone number is a much stronger link to you than an ip for example. Signal requires access to a valid…
-
comment
Comment #29873459
> How should that be possible if OMEMO is enabled (which is the default in more modern clients)? See https://infosec-handbook.eu/articles/xmpp-aitm/#t5 TL;DR: XMPP clients can't di…
-
comment
Comment #29873408
> What would be your alternative? A good starting point would be more balanced articles also talking about downsides or not-so-secure/-private defaults; not only in case of XMPP bu…
-
comment
Comment #29873020
> XMPP is as secure as Signal nowadays, it implements the same encryption scheme Signal enforces E2EE, you can't disable it. If XMPP supports E2EE depends on the XMPP clients and s…
-
comment
Comment #29872880
The article describes XMPP as "secure" by highlighting TLS (protecting data in transit only) and experimental OMEMO (protecting a small part of an XMPP message only if enabled and …
-
comment
Comment #29158069
The guide is outdated if you rely on the latest version of OpenSSH. You must update such guides with every new version of OpenSSH. Adding legacy configuration to your OpenSSH confi…
-
comment
Comment #29115871
> Almost none of the XMPP clients use plain text connection nowadays. Everything shown in the article works with or without TLS enabled. It doesn't matter. The server-side party se…
-
comment
Comment #29115840
Excellent example for what we mean: Our article doesn't discuss anything about "What is needed to register for service X." Discussing this is perfectly valid; however, it isn't abo…
-
comment
Comment #29109276
> If you recommend X instead of Y, it seems reasonable to discuss not only the downsides of Y but also how X is better or worse in comparison to Y. Indeed. One should mention upsid…
-
comment
Comment #29106443
> I believe you're slightly misunderstanding the details here (no surprise, as the article is not clear). The article clearly mentions that passwords are sent in cleartext to the s…