beep downgrade attacks...
Stephen Farrell <[email protected]> Fri, 31 May 2002 11:59:26 +0100
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Hi Simon, Have you a pointer to the details of a beep downgrade attack? Stephen. Simon Josefsson wrote: > > Stephen Farrell <[email protected]> writes: > > > C. Change the protocol draft to use something we know won't get > > stuck in the IESG for process reasons. Magnus made a specific > > suggestion for this previously that we'd have to finalise on > > the list in the event we get clear concensus on this option > > (which we need to get to proceed with it). > > C, using TLS + DIGEST-MD5. > > Btw, I note that BEEP is subject to downgrade attacks, is this > something that we should be concerned about? I could not find a > particular requirement that would fit that problem in RFC 3157, so > perhaps not. -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com