Re: beep downgrade attacks...

Alexey Melnikov <[email protected]> Fri, 31 May 2002 05:33:55 -0600
Newsgroups gmane.ietf.sacred
Organization ACI WorldWide / MessagingDirect
Message-ID <[email protected]>
Stephen Farrell wrote:

> Hi Simon,
>
> Have you a pointer to the details of a beep downgrade attack?

I suspect Simon was talking about man-in-the-middle removing strong SASL
mechanisms and/or TLS profile from the list advertised by the other
peer.

This is not specific for BEEP, all other protocols have the same issue
(LDAP, IMAP, POP3, ACAP, ...).

> Stephen.
>
> Simon Josefsson wrote:
> >
> > Stephen Farrell <[email protected]> writes:
> >
> > > C. Change the protocol draft to use something we know won't get
> > > stuck in the IESG for process reasons. Magnus made a specific
> > > suggestion for this previously that we'd have to finalise on
> > > the list in the event we get clear concensus on this option
> > > (which we need to get to proceed with it).
> >
> > C, using TLS + DIGEST-MD5.
> >
> > Btw, I note that BEEP is subject to downgrade attacks, is this
> > something that we should be concerned about?  I could not find a
> > particular requirement that would fit that problem in RFC 3157, so
> > perhaps not.

Regards,
Alexey Melnikov
__________________________________________
R & D, ACI Worldwide/MessagingDirect
Richmond, Surrey, UK
Phone: +44 20 8332 4508
Home Page: http://orthanc.ab.ca/mel

I speak for myself only, not for my employer.
__________________________________________