Re: beep downgrade attacks...
Simon Josefsson <[email protected]> Fri, 31 May 2002 14:33:59 +0200
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
From the security considerations of RFC 3080: ,---- | 1. A man-in-the-middle may remove the security-related profiles | from the BEEP greeting or generate a negative reply to the | "ready" element of the TLS transport security profile. A | BEEP peer may be configurable to refuse to proceed without an | acceptable level of privacy. `---- I am sorry if I'm misinterpreting this. I agree with Alex that the same problem exists in LDAP, IMAP etc, but SACRED is a security protocol. Since I couldn't find a requirement for protecting against these attacks in SACRED, perhaps there is no need to worry. /Simon Stephen Farrell <[email protected]> writes: > Hi Simon, > > Have you a pointer to the details of a beep downgrade attack? > > Stephen. > > > Simon Josefsson wrote: >> >> Stephen Farrell <[email protected]> writes: >> >> > C. Change the protocol draft to use something we know won't get >> > stuck in the IESG for process reasons. Magnus made a specific >> > suggestion for this previously that we'd have to finalise on >> > the list in the event we get clear concensus on this option >> > (which we need to get to proceed with it). >> >> C, using TLS + DIGEST-MD5. >> >> Btw, I note that BEEP is subject to downgrade attacks, is this >> something that we should be concerned about? I could not find a >> particular requirement that would fit that problem in RFC 3157, so >> perhaps not. > > -- > ____________________________________________________________ > Stephen Farrell > Baltimore Technologies, tel: (direct line) +353 1 881 6716 > 39 Parkgate Street, fax: +353 1 881 7000 > Dublin 8. mailto:[email protected] > Ireland http://www.baltimore.com