Re: Serious design flaw in STARTLS documents

John Gardiner Myers <[email protected]> Tue, 21 Apr 1998 16:58:51 -0700
Newsgroups gmane.ietf.apps-tls
Organization Netscape Communications Corporation
Message-ID <[email protected]>
Paul Hoffman / IMC wrote:
> Specifically, if none of the other extensions announced are
> security-related, forcing a new EHLO is wasteful.

Are you sure client implementors are going to correctly determine which
announced extensions are security-critical?  For example, PIPELINING is
potentially security-critical.  If an attacker can convince a client
that a server supports PIPELINING, when in fact the server does not,
this can cause Bad Things to happen.