micah micah at riseup.net
Mon Mar 2 19:20:15 CET 2015

Matthew Wild <mwild1 at gmail.com> writes:

> And the other problem is... even though they appear to be the
> defaults, Pepi's configuration has a mistake in it.

What is that mistake?

For additional security, I recommend disabling the 'version' module
(people dont need to determine the operating system version of the xmpp
server), 'time' (especially when running a tor hidden service), and
'pep' modules (this sends special XMPP messages that aren't being
handled by OTR, has potential for leaks).

Speaking of OTR, I recommend installing this module to push people
towards using OTR all the time:


You have the option of making it mandatory, or optional with a first
message "nag". The first one is hard, but it can be done if you start
that way, the second is a good reminder for people.


