@chewie @zeank See, my second toot here is about XMPP server, not about TURN server ;-)
> what would be the incentive to hack an xmpp account? To send SPAM? That’s usually done by creating accounts on servers having open registration
In my country the hacked XMPP account could be used to sell illegal drugs — I heard that drug addicts and dealers sometimes are using Jabber to communicate.
Or, in a more common way — hacked XMPP account could be used to frame the person as a criminal or terrorist — by some foreign hackers or even by police or security services, if they want an "easy case".
It is not a big deal for some corrupted official — upload something like child pornography or texts with government criticism using hacked account on the server, then raid the person's home to sieze the server and "prove" the person's guilty this way. You can earn an easily closed case and good department statistics this way.
Maybe you heard about similar case with mathematician Dmitry Bogatov? Unknown bad guy posted calls for mass unrest in some forums using his Tor exit-node and the state tried to put the Dmitry in jail for terrorism and mass riots preparation.
So, I'm very surprised that I don't see attempts to break in my Prosody installation in the logs.
#Jabber #XMPP