Re: TLS cipersuites for Rserpool

Melinda Shore <[email protected]>
Newsgroups gmane.ietf.rserpool
Message-ID <[email protected]>
On Monday, September 15, 2003, at 06:44 PM, bill wrote:
> Ok, first by making "the new cypher on the block" the only MUST
> implement we get into a situation where AES might become broken, and
> therefor we have a problem.

This has been discussed fairly extensively in saag, and the
consensus was that AES should be mandatory-to-implement in
new protocols and what to do about 3DES was an open question.

A bigger problem than the possibility of a cipher being
compromised, I think, is that when you've got multiple ciphers
providing different degrees of protection you've got the
possibility of a bid-down attack, which is a protocol attack
and frankly more accessible.  If more than one cipher is
to be specified we need to be explicit about how they're
requested/signaled and to make sure that it's resilient against
that particular type of attack.

Melinda
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.