@MauroV1968 I would rephrase saying that “learning how and when to questioning science is how you learn to do science”. Because scientific endeavour is not necessarily questioning previous works, but also building upon them, and not necessarily breaking old paradigms, but also discover new ones. #scicomm
@muppeth@mattj@fluchtkapsel Sticking with LDAP would at least on paper leave the door open for channel binding.
2FA could be added to XMPP w/o involving web stack stuff.
I'm not fundamentally opposed to oauth. I'm just pointing out that the use case of oauth is convenience rather than added security. If we implement it wrong me might even loose security (channel binding).
Here is my use case. I use LDAP for authentication and currently in the process of adding keycloak for oidc. XMPP at this point needs to stay with LDAP only, while it would be an added feature for me if it would support openid
@fluchtkapsel Authenticating with oauth with a third party is not currently available. @mattj probably has the most insights into what steps we made into that direction yet.
Part of the problem is that we loose nice security features like channel binding by using web stuff.
Re-introduction time! Hello fediverse, I am Nina! I'm mainly a pixel artist, but have been doing some web dev work for most of the last year.I do everything, but enjoy character work and icon work the most. My job has me posting much less public art at the moment, so my account is a lot of rambles, but that's just how it is!You can find my current commission status at https://misnina.com#Introduction #PixelArt #MastoArt