#XSF Announcement
Recently there was an incident via a so called #man_in_the_middle attack happened to an #XMPP #server.
To reduce the risk of such attacks in the future an early stage service called CertWatch has been published by our Community: certwatch.xmpp.net/
Many thanks to Stephen P. Weber (@singpolyma)!
Read two related blog posts:
blog.jmp.chat/b/certwatch/cert…
snikket.org/blog/on-the-jabber…
#Jabber #mitm #security #vulnerability #machine_in_the_middle #chat
On the jabber.ru MITM attack
Reports of a possible recent interception of the public XMPP service jabber.ru have raised a lot of questions for people about how the attack happened, and whether it could affect them too. We have some answers.snikket.org
This entry was edited (1 year ago)
Nicoco reshared this.
ruff
in reply to XSF: XMPP Standards Foundation • • •Ryuno-Ki
in reply to XSF: XMPP Standards Foundation • • •An alternative form of MitM is Manipulator-in-the-middle.
I prefer it as it is (1) more accurate and (2) less focused on a gender („man“ being ambiguous in English here).
Colin Cogle 🔵
in reply to XSF: XMPP Standards Foundation • • •Klaus Alexander Seistrup
in reply to XSF: XMPP Standards Foundation • • •#XMPP #CertWatch said that »[My] settings are correct and no MITM was detected.« That's great.
It then continued with some #PubSub stuff and finally said »If you do not have a pubsub-capable client you can subscribe for text notifications by opening a chat with certwatch.xmpp.net and sending the message “subscribe <my xmpp server>”«.
My question is now: How do I open a chat with a hostname and not a JID?
My clients are #Gajim resp. #Conversations / #BlabberIM.
Anyone?
CertWatch: XMPP MITM Monitoring
certwatch.xmpp.netDaniel Gultsch
in reply to Klaus Alexander Seistrup • • •@kas exactly like you would open a chat with a contact. Or by clicking here: xmpp:certwatch.xmpp.net
Conversations shows a warning that this is a domain address but 'add anyway' works fine.
Debacle
in reply to Daniel Gultsch • • •@daniel @kas @mdosch
Seems not to work with #Gajim by @gajim, but with #Dino by @dino.
Gajim
in reply to Debacle • • •