[Bug 308181]
Ben-bucksch
308181 at bugs.launchpad.net
Wed Apr 9 10:24:29 UTC 2025
> DNS MX record ... is just as vulnerable as looking up DNS SRV records
Yes, but we use MX only as fallback when we cannot get the config
directly. If possible, we use HTTPS from the provider directly, or
ISPDB, which is also HTTPS. But you're recommending to replace these
secure mechanisms with the less secure DNS SRV:
> by supporting RFC 6186, we could potentially remove at least 9 config
files from the ISPDB
In addition, DNS SRV does not provide a solution for reason 3 in comment
63. DNS SRV only provides hostname and port. It's simply lacking the
majority of the information: username form, authentication method,
OAuth2 server etc.pp.. Scrambling and guessing and try&error are not a
solution, esp. when it comes to login, and considering the
multiplication of the various factors - that's what we did 15 years ago,
before AutoConfig, and it did not work, that's why I invented AutoConfig
in the first place.
--
You received this bug notification because you are a member of Mozilla
Bugs, which is subscribed to Mozilla.
https://bugs.launchpad.net/bugs/308181
Title:
xmpp4moz doesn't read SRV DNS records
To manage notifications about this bug go to:
https://bugs.launchpad.net/sameplace/+bug/308181/+subscriptions
More information about the Ubuntu-mozillateam-bugs
mailing list