beep downgrade attacks...

Stephen Farrell <[email protected]> Fri, 31 May 2002 11:59:26 +0100
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

Hi Simon,

Have you a pointer to the details of a beep downgrade attack?

Stephen.


Simon Josefsson wrote:
> 
> Stephen Farrell <[email protected]> writes:
> 
> > C. Change the protocol draft to use something we know won't get
> > stuck in the IESG for process reasons. Magnus made a specific
> > suggestion for this previously that we'd have to finalise on
> > the list in the event we get clear concensus on this option
> > (which we need to get to proceed with it).
> 
> C, using TLS + DIGEST-MD5.
> 
> Btw, I note that BEEP is subject to downgrade attacks, is this
> something that we should be concerned about?  I could not find a
> particular requirement that would fit that problem in RFC 3157, so
> perhaps not.

-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com