xmpp, icon when Server connection is secure (TLS)

Bria for iPhone / iPad User to User Support Forum

Moderators: aolive, Bogdan, Arthur, CGirardot, yukiko, Mike McMullen

xmpp, icon when Server connection is secure (TLS)

Postby asdf1234 » Thu Jul 05, 2012 1:12 am

Hi,

is there any way to see in the bria im client if the xmpp connection to the server is using TLS ? I think it would be nice to know if the transport is encrypted. A small icon like a padlock in the status bar would be nice.

Regards
asdf1234
asdf1234
 
Posts: 22
Joined: Thu Apr 07, 2011 1:25 am
Location: Hamburg, Germany

Re: xmpp, icon when Server connection is secure (TLS)

Postby Bogdan » Thu Jul 05, 2012 6:32 am

As far as i know "all" XMPP servers uses TLS.
Bogdan
CounterPath Engineering
 
Posts: 1356
Joined: Thu Feb 03, 2005 4:23 pm

Re: xmpp, icon when Server connection is secure (TLS)

Postby asdf1234 » Thu Jul 05, 2012 7:05 am

i thought only the negotiation via STARTTLS is mandatory. A client can decide to not use TLS or negotiation of TLS can fail. (RFC6120 section 5).

If that is the case how would the user know ?

Regards
asdf1234
asdf1234
 
Posts: 22
Joined: Thu Apr 07, 2011 1:25 am
Location: Hamburg, Germany

Re: xmpp, icon when Server connection is secure (TLS)

Postby Bogdan » Thu Jul 05, 2012 7:16 am

Our client requests TLS.
Bogdan
CounterPath Engineering
 
Posts: 1356
Joined: Thu Feb 03, 2005 4:23 pm

Re: xmpp, icon when Server connection is secure (TLS)

Postby asdf1234 » Thu Jul 05, 2012 8:07 am

i just setup a test xmpp server locally and disabled tls. The Bria client happily connected using SASL authentication (which is secure) but the contents of the send messages and signalling etc. where unencrypted as expected, so i think a icon which informs the user whether or not the connection is secure would be a nice thing.

Regards
asdf1234
asdf1234
 
Posts: 22
Joined: Thu Apr 07, 2011 1:25 am
Location: Hamburg, Germany

Re: xmpp, icon when Server connection is secure (TLS)

Postby Bogdan » Thu Jul 05, 2012 8:36 am

PErhaps indicator would be good.
But notice that you forced on server to disable TLS.
This is not what real servers do.

Meaning that this is not app to the app (as opposed to SIP).
I don't think that managed systems e.g. Skype provides such indicators.
Bogdan
CounterPath Engineering
 
Posts: 1356
Joined: Thu Feb 03, 2005 4:23 pm

Re: xmpp, icon when Server connection is secure (TLS)

Postby asdf1234 » Thu Jul 05, 2012 11:03 am

I can think of many actions like intercepting port 5222 connections (public hotspots for example) and altering the connection atemps to stay plaintext and read all the messages that pass through. If you have an indicator for encryption and "verify ssl certs' in combination you can be pretty sure no one is tampering with your connection.

See the Whatsapp sniffer application for android for example that proxyarps all traffic through the attackers device and capture all messages traveling through the wifi network.

P.s: i don't really care about closed systems like skype, no one really considers that a solution for business applikations.

Regards
asdf1234
asdf1234
 
Posts: 22
Joined: Thu Apr 07, 2011 1:25 am
Location: Hamburg, Germany


Return to Bria iPhone / iPad Edition

Who is online

Users browsing this forum: No registered users and 1 guest