7 points Bender 3 hours ago No comments
Related to this thread [1] which Jabber clients not only detect MitM tampering when a valid cert is used in the middle but is not the cert on the server, meaning an entity obtained a certificate, used it to MitM the connection and the client not only rejects this alternate valid certificate but also alerts the user to the MitM. XEP-0474 SASL SCRAM Downgrade Protection (Experimental) [2] Claude does not seem to know and I can't find any clarifying documentation, just lots of open issues.
The purpose is for writing an article on E2EE but I want to suggest clients that will alert on MitM tampering in a manor the person using the client can not accidentally ignore it. i.e. just click through a warning
On the server side eJabberd and Prosody appear to be the only server daemons supporting XEP-0474 but I just can't find a definitive list of supported clients even if they are in the experimental phase. One may wish to experiment.
[1] - https://news.ycombinator.com/item?id=37955264
[2] - https://xmpp.org/extensions/xep-0474.html