@FiXato @fedilab The password before saving should still go to the ejabberd API. After that, it is stored in a salted hash. Ejabberd can trim the layout in an unfamiliar language and the password just won't be saved.
Conversation
Notices
-
404.city (404city@mastodon.social)'s status on Monday, 17-Jun-2019 00:19:55 UTC 404.city -
404.city (404city@mastodon.social)'s status on Monday, 17-Jun-2019 01:10:33 UTC 404.city @FiXato @fedilab @FiXato @fedilab When using hashing, the method SCRAM-SHA1 is always present. In the absence of hashing SCRAM-SHA1 is always missing.
Example:
404.city stores passwords in ONLY SCRAM-SHA1. Disroot stores password ONLY PLAIN text. Proof: https://xmpp.net/result.php?domain=disroot.org&type=client -
404.city (404city@mastodon.social)'s status on Monday, 17-Jun-2019 03:55:37 UTC 404.city @FiXato @fedilab @FiXato @fedilab When using hashing, the method SCRAM-SHA1 is always present. In the absence of hashing SCRAM-SHA1 is always missing.
Example:
404.city stores passwords in ONLY SCRAM-SHA1. Disroot stores password ONLY PLAIN text. Proof: https://xmpp.net/result.php?domain=disroot.org&type=client
-