[JDEV] Transports and unregistered Jabber accounts

Matthias Wimmer m at tthias.net
Thu Jan 8 04:07:48 CST 2004


Hi!

Trejkaz Xaoza schrieb am 2004-01-07 21:48:40:
> > The result is, that an other person can register for the same account
> > and use the former users transport without reregistering and without
> > knowing the password used to register the accounts.
> Are you sure about this?  Can the new user simply add a transport straight to 
> their roster?  I was under the impression that the only way to add a 
> transport was via registration with the transport, which should require the 
> password.

Yes they can. This will not work if the transport is not registered, but
if it is registered and just removed, it will work.

> An ostrich approach to solving the problem would be not to allow removal of 
> accounts.  This approach seems good enough for every other IM service on the 
> planet so it's probably good enough for a Jabber server, assuming it's 
> actually possible.

With Yahoo! you can delete your account. Removing the ability to delete
accounts would make it impossible to operate Jabber servers in some
countries. AFAIK a user has to be given the right to delete his accounts
in the EU.


Tot kijk
    Matthias

-- 
Fon: +49-(0)70 0770 07770       http://matthias.wimmer.name/
HAM: DB1MW                      xmpp:mawis at charente.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: <https://www.jabber.org/jdev/attachments/20040108/be6a2584/attachment-0002.pgp>


More information about the JDev mailing list