Re: Man In The Middle Attacks and STARTTLS
Paul Hoffman / IMC <[email protected]> Thu, 15 Apr 1999 14:33:26 -0700
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
At 02:01 PM 4/15/99 -0700, Dan Wing wrote: >I think you can protect against this attack, but you do need to describe >how in the security considerations section. > >To protect against the MITM attack you describe below, the client needs to >treat "454 TLS not available due to temporary reason" exactly the same as >a missing "250 STARTTLS" from the EHLO response. That's my conclusion. It also means that watching for the lack of "250 STARTTLS" doesn't buy you anything. --Paul Hoffman, Director --Internet Mail Consortium