Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Ask HN: Which Jabber clients support SCRAM+ and XEP-0474
8 points by Bender 4 hours ago | hide | past | favorite | discuss
Related to this thread [1] which Jabber clients not only detect MitM tampering when a valid cert is used in the middle but is not the cert on the server, meaning an entity obtained a certificate, used it to MitM the connection and the client not only rejects this alternate valid certificate but also alerts the user to the MitM. XEP-0474 SASL SCRAM Downgrade Protection (Experimental) [2] Claude does not seem to know and I can't find any clarifying documentation, just lots of open issues.

The purpose is for writing an article on E2EE but I want to suggest clients that will alert on MitM tampering in a manor the person using the client can not accidentally ignore it. i.e. just click through a warning

On the server side eJabberd and Prosody appear to be the only server daemons supporting XEP-0474 but I just can't find a definitive list of supported clients even if they are in the experimental phase. One may wish to experiment.

[1] - https://news.ycombinator.com/item?id=37955264

[2] - https://xmpp.org/extensions/xep-0474.html

 help



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: