RE: Sub/Not Security, Presence service identifiers
"Mark Day" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
> > It's OK to have a timestamp for when a notification is sent. > Does every one think that notification requests should be timestamped? > > An answer of yes implies nothing about whether you think the timestamp > should be signed. When I said that it was "OK", I was only meaning that it doesn't appear to introduce any new problems if you allow a timestamp on a notification. I didn't mean to express that I thought it was desirable. I'm not really sure what value it adds. I suppose it lets you know something about how timely notification delivery is if you trust it (whether because of a signature or because you're a trusting sort). Is that important? Since the London meeting, the WG has been following a "minimalist" guideline that nothing goes into our protocols and formats unless it's either clearly in 2778/2779 or *required* for correct operation. I don't think a notification timestamp makes the cut. Specifically, I don't think such a timestamp adds much as a security mechanism against the Alice/Bob/Eve attack example, as I've indicated in previous messages. --Mark [reminder: [email protected] for non-technical discussions, please]