LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-09-2011, 03:16 PM   #1
Xeratul
Senior Member
 
Registered: Jun 2006
Location: UNIX
Distribution: FreeBSD
Posts: 2,657

Rep: Reputation: 255Reputation: 255Reputation: 255
Is using JABBER really secured?


Hi,

Everyone on this board knows the technique of the man in the middle. I would like to start the discussion about jabber. http://www.jabber.org/

Is that really wise to use jabber, or psi, and so on?
http://lifehacker.com/289097/chat-wi...er-google-talk

Here find a shot of trusting, sometimes, blind'y...
Attached Thumbnails
Click image for larger version

Name:	psitrust.png
Views:	8
Size:	10.7 KB
ID:	5805  
 
Old 01-09-2011, 08:52 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
Your question seems to combine the protocol (jabber) and user acceptance of certificates (pki) which are 2 completely separate things - which one are you concerned about ?
 
1 members found this post helpful.
Old 01-09-2011, 09:57 PM   #3
Xeratul
Senior Member
 
Registered: Jun 2006
Location: UNIX
Distribution: FreeBSD
Posts: 2,657

Original Poster
Rep: Reputation: 255Reputation: 255Reputation: 255
Quote:
Originally Posted by kbp View Post
Your question seems to combine the protocol (jabber) and user acceptance of certificates (pki) which are 2 completely separate things - which one are you concerned about ?
You're right. thanks
- Well, actually Jabber is considered (in the title). Servers, jabbers, man in middle, and others
 
Old 01-10-2011, 07:47 PM   #4
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
Jabber (XMPP) supports TLS and SASL for encryption, there are several RFC's which cover different aspects of the protocol, the primary ones being - 3920, 3921, 3922, 3923. You may be interested in reading 3920 and 3923 (End-to-end signing and object encryption). I guess you would still be vulnerable to dns poisoning attacks (think MITM) but that's not really an issue with XMPP itself.

cheers
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What about non secured cmd lines through AIM ?? (ssh like, non secured) frenchn00b Debian 2 11-17-2008 01:52 AM
Jabber server (jabberd 1.4) does not uplink to main jabber hubs polemon Linux - Server 2 06-23-2007 04:43 PM
Guys Help me to be secured aq_mishu Linux - Security 14 03-26-2007 04:39 AM
Is Linux truly SECURED? poda Linux - Security 9 06-01-2005 08:04 PM
Secured Login bharaniks Linux - Newbie 4 05-30-2005 12:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration