On the state of SASL in XMPP
SASL (Simple Authentication and Security Layer) as used in XMPP is broken. In this blog post I鈥檒l try to explain why and propose some fixes. Update (2023-04-21): Since I originally wrote this blog post, I鈥檝e had the ability to discuss several of my ideas with Dave (the original author of XEP-0388 dubbed SASL2), MattJ (one of the authors of the prosody xmpp server) and others. Most, if not all, of my issues are now addressed in a bunch of updates to existing XEPs as well as new XEPs: ...