Re: beep downgrade attacks...

Simon Josefsson <[email protected]> Fri, 31 May 2002 14:33:59 +0200
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
From the security considerations of RFC 3080:

,----
|        1.  A man-in-the-middle may remove the security-related profiles
|            from the BEEP greeting or generate a negative reply to the
|            "ready" element of the TLS transport security profile.  A
|            BEEP peer may be configurable to refuse to proceed without an
|            acceptable level of privacy.
`----

I am sorry if I'm misinterpreting this.

I agree with Alex that the same problem exists in LDAP, IMAP etc, but
SACRED is a security protocol.  Since I couldn't find a requirement
for protecting against these attacks in SACRED, perhaps there is no
need to worry.

/Simon

Stephen Farrell <[email protected]> writes:

> Hi Simon,
>
> Have you a pointer to the details of a beep downgrade attack?
>
> Stephen.
>
>
> Simon Josefsson wrote:
>> 
>> Stephen Farrell <[email protected]> writes:
>> 
>> > C. Change the protocol draft to use something we know won't get
>> > stuck in the IESG for process reasons. Magnus made a specific
>> > suggestion for this previously that we'd have to finalise on
>> > the list in the event we get clear concensus on this option
>> > (which we need to get to proceed with it).
>> 
>> C, using TLS + DIGEST-MD5.
>> 
>> Btw, I note that BEEP is subject to downgrade attacks, is this
>> something that we should be concerned about?  I could not find a
>> particular requirement that would fit that problem in RFC 3157, so
>> perhaps not.
>
> -- 
> ____________________________________________________________
> Stephen Farrell         				   
> Baltimore Technologies,   tel: (direct line) +353 1 881 6716
> 39 Parkgate Street,                     fax: +353 1 881 7000
> Dublin 8.                mailto:[email protected]
> Ireland                             http://www.baltimore.com