XMPP Service Operators - 2019-10-25


  1. seantodd

    @version chat.seantodd.co.uk

  2. Echo1

    seantodd: chat.seantodd.co.uk is running Prosody version trunk nightly build 1158 (2019-10-20, cb9755d7a36e) on Linux

  3. seantodd

    @contact chat.seantodd.co.uk

  4. seantodd

    Hmm, does the bot have a command for pulling contact details? I'm just trying to make sure my server is user-friendly before pushing it to wider people.

  5. jonas’

    07:42:52 jonas’> !contact chat.seantodd.co.uk 07:42:55 foorl> jonas’: contact for chat.seantodd.co.uk: abuse: <mailto:abuse@seantodd.co.uk>, <xmpp:seantodd@chat.seantodd.co.uk> admin: <mailto:admin@seantodd.co.uk>, <xmpp:seantodd@chat.seantodd.co.uk> support: <mailto:support@seantodd.co.uk>, <xmpp:seantodd@chat.seantodd.co.uk>

  6. jonas’

    sgtm

  7. jonas’

    make sure you can receive messages from strangers on seantodd@chat.seantodd.co.uk

  8. Link Mauve

    seantodd, also, any reason you use this chat. subdomain? It might be nicer to have both your email and your XMPP addresses match.

  9. seantodd

    I believe I can! Its set in my client.

  10. seantodd

    And Link, it's a legacy domain. I'm looking to migrate soon-ish.

  11. Link Mauve

    Ok.

  12. seantodd

    Thanks for the assistance though peeps!

  13. jonas’

    seantodd, migrating is a pain in the a**

  14. jonas’

    you want to do this as early as possible

  15. seantodd

    jonas’: agreed. I'm considering just burning and reinitialising my entire chat stack. It'll give me chance to re-do my DNS entries too.

  16. seantodd

    jonas’: there aren't enough users to require a migration right now.

  17. Ge0rG

    Is there any info on which XMPP clients do/don't support ECDSA server certs?

  18. 404.city

    Ge0rG, yaxIM

  19. 404.city

    Ge0rG, yaxIM don't support. All other support

  20. perflyst

    Ge0rG: when dane in yaxim? :) i saw recently that aTalk supports it

  21. Licaon_Kter

    perflyst: if we go by what atalk supports yaxim/conversations/xabber should just close and go home Yet...

  22. perflyst

    nah, aTalk has 99% features but bad UI

  23. Licaon_Kter

    _I've got 99 features but a user ain't one_

  24. Ge0rG

    404.city: you mean yax.im the server, not yaxim the client, right?

  25. Ge0rG

    perflyst: DANE? Needs to come from Smack.

  26. 404.city

    Ge0rG, I mean the client YaxIM, not the server yax.im

  27. Ge0rG

    404.city: the client is yaxim, all lowercase ;)

  28. Ge0rG

    404.city: so you tell me yaxim won't connect to a server with an ECDSA cert? Do you have an error message?

  29. 404.city

    Ge0rG, I have no other information, except that the yaxim client does not connect to 404.city. The most likely reason is an ECC certificate

  30. Ge0rG

    404.city: thanks for reporting it. I'll investigate.

  31. Ge0rG

    However, yaxim is not doing anything special, so it is probably heavily dependent on the Android version.

  32. 404.city

    Ge0rG, Is Google's quantum computer hacking RSA?

  33. Ge0rG

    404.city: NSA has hacked DSA

  34. Ge0rG

    404.city: I've just logged in from yaxim to 404.city

  35. Ge0rG

    the only thing that doesn't work is MUC search, because it needs s2s to yax.im

  36. 404.city

    Ge0rG, I love when mistakes disappear, without any action

  37. Ge0rG

    404.city: I hate it. Because they don't really disappear, they will come back later and bite you

  38. Ge0rG

    404.city: I'll probably reconsider the deactivation of ECDSA handshakes on yax.im, which will then restore direct connectivity to 404.city

  39. Licaon_Kter

    Wasn't ECDSA using some messed up primes or smth?

  40. 404.city

    Licaon_Kter, Yes, they used to. RSA also uses. Lets Encrypt also followed NSA orders.

  41. Licaon_Kter

    U trolling now or just fud as usual?

  42. 404.city

    If we talk about protecting the CA from the NSA, then it is complete crap, but this complete crap works well against third countries.

  43. 404.city

    Licaon_Kter, No, this is not trolling. There are facts exist.

  44. 404.city

    Example: https://xmpp.net/result.php?domain=yax.im&type=server ECDHE-RSA . What a mess, this is an ECC certificate))

  45. 404.city

    I did not find evidence with Lets Encrypt, but very often there are rumors that Lets issued fake certificates for hacking Arabs.

  46. Ge0rG

    Licaon_Kter: ECDSA is technically flawed, because it's neigh impossible to implement correctly

  47. Ge0rG

    https://minerva.crocs.fi.muni.cz/ is the last one in a series of practical attacks against ECDSA

  48. Ge0rG

    the most embarassing one, however, is this: https://medium.com/asecuritysite-when-bob-met-alice/not-playing-randomly-the-sony-ps3-and-bitcoin-crypto-hacks-c1fe92bea9bc

  49. 404.city

    Ge0rG, In practice, you can implement an attack on any certificate if you are CA

  50. Ge0rG

    404.city: that's wrong. You can implement an attack on any *domain* if you are a CA

  51. Ge0rG

    404.city: however, with Certificate Transparency and HSTS it's getting increasingly harder.

  52. 404.city

    CA centers are completely subordinate to the governments of the countries where their location. RSA and ECC certificates are equally unreliable against CA attacks. Recently, there has been a massive transition to ECC certificates, because they are more resistant to cracking by quantum computers. RSA has a maximum bit rate of 4096 bit. 512 bit ECC equivalent to 16,000 bit RSA

  53. perflyst

    404.city: so everyone should self sign again?

  54. perflyst

    if you dont like CAs as you think they are gov spy companies, what about your manifesto to distrust everyone else https://github.com/E-404/Manifestos/blob/master/1.md ?

  55. Ge0rG

    404.city: what you have said has nothing to do what I asked about.

  56. 404.city

    >perflyst‎: 404.city: so everyone should self sign again? To solve these problems, there is e2e encryption

  57. Ge0rG

    I'm still interested in knowing which clients I'll cut off by switching from an RSA cert to ECDSA

  58. Ge0rG

    apparently, Android 4.1 is required for ECDSA support

  59. Ge0rG

    But I'm sure there are others that will get cut off

  60. 404.city

    >perflyst‎: if you dont like CAs as you think they are gov spy companies, what about your manifesto to distrust everyone else Self-signed certificates are the worst option. Self-signed certificates, this is a complete lack of encryption. There is not always a choice between the best and the worst. Sometimes there is a choice between bad and very bad. CAs protect against hacking from third countries where CA is not located. Self-Signing Won't Protect From Public Wi-Fi

  61. Ge0rG

    Sigh.

  62. 404.city

    Ge0rG‎: Most client and servers support ECC. The transition is invisible to most users

  63. 404.city

    Ge0rG, Your server has many users with a yaxim client, so you should pay attention only to this client

  64. Link Mauve

    404.city, I remember when some Ejabberd admins switched to ECC certificates, it broke s2s with my servers.

  65. Link Mauve

    This has probably been fixed since then, but not everyone updates as quickly.

  66. Ge0rG

    Link Mauve: do you have s2s to 404.city?

  67. Link Mauve

    Yes.

  68. Link Mauve

    I’m talking about multiple years ago.

  69. Ge0rG

    404.city [19:08]: > Ge0rG, Your server has many users with a yaxim client, so you should pay attention only to this client Yes, it's a great idea to ignore all users not running a certain unpopular implementation.

  70. 404.city

    Link Mauve, Some administrators manually list ciphers and forget to mention RSA when using ECC and vice versa. I encountered the same problem when using RSA. However, I was persuaded to switch to ECC. The reason is that supposedly CA will soon switch to ECC, which makes the long-term use of RSA meaningless.

  71. Link Mauve

    Ge0rG, but there are still people starting to run Prosody 0.9.7 today, with an equally outdated software stack.

  72. Ge0rG

    Link Mauve: ITYM Debian

  73. Link Mauve

    You read my mind!

  74. 404.city

    Ge0rG, Possible problems may occur with users with Windows XP

  75. Ge0rG

    404.city: do you have a list of clients that do / don't support ECDSA? Did you see a change in numbers when you switched?

  76. 404.city

    Ge0rG, I did not notice any changes in the number of connections, but it is worth noting that 404.city b did not allow users with Windows XP to connect before.

  77. Ge0rG

    Does XP support TLS 1+?

  78. 404.city

    Ge0rG, Only user with yaxim and UWPX reported connection problems. Currently there are user connections with new version UXPX.

  79. Ge0rG

    404.city: do you still have contact to the yaxim user? I'd appreciate a bug report.

  80. 404.city

    Ge0rG, I don’t know, but a lot of people (10%) fell off after receiving a 100% RSA certificate at xmpp.net They all reported that they have Windows XP

  81. 404.city

    Ge0rG, I don’t remember who this man was. It was a long time ago.I will forward the yaxim errors to you.

  82. Ge0rG

    https://blog.intothesymmetry.com/2019/08/side-channel-timing-attacks-against.html it'll never stop

  83. Ge0rG

    404.city: thanks!