[Bug 308181]

Ben-bucksch 308181 at bugs.launchpad.net
Wed Apr 9 10:24:29 UTC 2025


> DNS MX record ... is just as vulnerable as looking up DNS SRV records

Yes, but we use MX only as fallback when we cannot get the config
directly. If possible, we use HTTPS from the provider directly, or
ISPDB, which is also HTTPS. But you're recommending to replace these
secure mechanisms with the less secure DNS SRV:

> by supporting RFC 6186, we could potentially remove at least 9 config
files from the ISPDB

In addition, DNS SRV does not provide a solution for reason 3 in comment
63. DNS SRV only provides hostname and port. It's simply lacking the
majority of the information: username form, authentication method,
OAuth2 server etc.pp.. Scrambling and guessing and try&error are not a
solution, esp. when it comes to login, and considering the
multiplication of the various factors - that's what we did 15 years ago,
before AutoConfig, and it did not work, that's why I invented AutoConfig
in the first place.

-- 
You received this bug notification because you are a member of Mozilla
Bugs, which is subscribed to Mozilla.
https://bugs.launchpad.net/bugs/308181

Title:
  xmpp4moz doesn't read SRV DNS records

To manage notifications about this bug go to:
https://bugs.launchpad.net/sameplace/+bug/308181/+subscriptions




More information about the Ubuntu-mozillateam-bugs mailing list