问HN:哪些Jabber客户端不仅支持SCRAM+和XEP-0474?

1 分•作者: Bender•2 个月前•原帖
与此线程相关 [1],哪些 Jabber 客户端不仅在中间使用有效证书时能够检测到中间人攻击(MitM)篡改,但该证书并不是服务器上的证书,这意味着某个实体获取了一个证书,并利用它进行中间人攻击,客户端不仅拒绝这个替代的有效证书,还会提醒用户存在中间人攻击。XEP-0474 SASL SCRAM 降级保护 <i>(实验性)</i> [2],Claude 似乎并不知道,而我也找不到任何澄清的文档,只有很多未解决的问题。 <p>这篇文章的目的是关于端到端加密(E2EE),但我想建议一些能够在中间人攻击篡改时发出警报的客户端,以一种用户无法意外忽视的方式。<i>即:仅仅点击警告即可通过</i> <p>[1] - https://news.ycombinator.com/item?id=37955264 <p>[2] - https://xmpp.org/extensions/xep-0474.html
查看原文
Related to this thread [1] which Jabber clients not only detect MitM tampering when a valid cert is used in the middle but is not the cert on the server, meaning an entity obtained a certificate, used it to MitM the connection and the client not only rejects this alternate valid certificate but also alerts the user to the MitM. XEP-0474 SASL SCRAM Downgrade Protection <i>(Experimental)</i> [2] Claude does not seem to know and I can&#x27;t find any clarifying documentation, just lots of open issues.<p>The purpose is for writing an article on E2EE but I want to suggest clients that will alert on MitM tampering in a manor the person using the client can not accidentally ignore it. <i>i.e. just click through a warning</i><p>[1] - https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37955264<p>[2] - https:&#x2F;&#x2F;xmpp.org&#x2F;extensions&#x2F;xep-0474.html