top | item 38003207

(no title)

xnyhps | 2 years ago

Will modern clients warn loudly if a server suddenly stops offering channel binding? Otherwise it is trivial to downgrade.

discuss

order

MattJ100|2 years ago

They do, yes. It's certainly a requirement if channel binding is to work at all.

Additionally there is this proposal to also detect attempted downgrade of the channel binding and SASL mechanism lists themselves: https://xmpp.org/extensions/xep-0474.html - which we're currently looking for expert eyes on, if you know any... :)