Re: beep downgrade attacks...
Alexey Melnikov <[email protected]> Fri, 31 May 2002 05:33:55 -0600
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | ACI WorldWide / MessagingDirect |
| Message-ID | <[email protected]> |
Stephen Farrell wrote: > Hi Simon, > > Have you a pointer to the details of a beep downgrade attack? I suspect Simon was talking about man-in-the-middle removing strong SASL mechanisms and/or TLS profile from the list advertised by the other peer. This is not specific for BEEP, all other protocols have the same issue (LDAP, IMAP, POP3, ACAP, ...). > Stephen. > > Simon Josefsson wrote: > > > > Stephen Farrell <[email protected]> writes: > > > > > C. Change the protocol draft to use something we know won't get > > > stuck in the IESG for process reasons. Magnus made a specific > > > suggestion for this previously that we'd have to finalise on > > > the list in the event we get clear concensus on this option > > > (which we need to get to proceed with it). > > > > C, using TLS + DIGEST-MD5. > > > > Btw, I note that BEEP is subject to downgrade attacks, is this > > something that we should be concerned about? I could not find a > > particular requirement that would fit that problem in RFC 3157, so > > perhaps not. Regards, Alexey Melnikov __________________________________________ R & D, ACI Worldwide/MessagingDirect Richmond, Surrey, UK Phone: +44 20 8332 4508 Home Page: http://orthanc.ab.ca/mel I speak for myself only, not for my employer. __________________________________________