FW: DISCUSS: draft-ietf-ipcdn-bpiplus-mib

"Wijnen, Bert (Bert)" <[email protected]>
Newsgroups gmane.ietf.ipcdn
Message-ID <7D5D48D2CAA3D84C813F5B154F43B15503C79CD5@nl0006exch001u.nl.lucent.com>
FYI and possible follow up

-----Original Message-----
From: Steve Bellovin [mailto:[email protected]]
Sent: Thursday, September 23, 2004 20:07
To: [email protected]
Subject: DISCUSS: draft-ietf-ipcdn-bpiplus-mib


I concur in Russ' comments about the lack of any suitably strong crypto 
algorithms.  40-bit DES is, frankly, an embarrassment at this point.  
Yes, I realize that DOCSIS isn't doing it right yet; that's no reason 
for us to do it wrong.  We should put the code points into the MIB now, 
and let them catch up.  But I'll let Russ hold that part of the DISCUSS 
(as well as the note that authentication algorithms are needed.)

The Security Considerations section says

    The time to crack DES could be additionally
    mitigated by a compromised value for the TEK lifetime and Grace Time
    (up to a minimum of 30 minutes for the TEK lifetime, see
    Appendix A [1]).

That's only partially correct.  These keys are confidentiality keys; 
they're still valuable even after they're no longer in active use, 
because they can be used to decrypt old traffic.  (By contrast, old 
authentication keys are useless to an attacker.)

		--Steve Bellovin, http://www.research.att.com/~smb
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.