|
|
|
|
|
by blibble
4512 days ago
|
|
so we've had a solution to the credential sniffing for 10+ years: our services support AUTH via something very similar to CRAM-MD5. with that out of the way: you've missed the main point, and that is that it's really really hard (I would use the word impossible but I'm not 100% certain) to secure multiuser chat. the sheer number of places that could be compromised is so high, that offering a 'secure connection' (which users associate with actually secure online commerce) is dangerously misleading. we understand the threat model very well, and we recommend that you shouldn't trust us to secure your communications, and suggest something like fish instead. |
|
We are not asking the Quakenet staff to "fix" multiuser chat encryption - leave that to the protocol developers, researchers and people working on different experimental protocols to try to "fix".
But, I still don't understand how much you refuse to step into reality and face that SSL is nice to have on a modern IRC network - we agree that it's not perfect, but do allow your users to understand the risk and let them take the necessary step to enhance the privacy of their communication.
Right now you are just hindering it where every other network is way ahead of you in this regard...
Your users are not dumb. I, as a user, want to be able to decide whether or not I connect, to a network, over SSL, where I assume that the network is able to interconnect its servers over SSL encrypted links, then I can make the decision if I want to add an extra layer of security by using software like FiSH where I can share secrets with my closets friends using, say, a pre-shared key.
Please, stop assuming that us users are idiots.