Re: Still missing: TLS_ECDH_anon_WITH_AES_xxx_GCM_SHAxxx

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.tls,gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C737238B6C3@uxcn10-6.UoA.auckland.ac.nz>
Alyssa Rowan <[email protected]> writes:

>Can we perhaps make that a SHOULD NOT (or even a MUST NOT), if it somehow
>isn't already? It's way too common in the wild, and it really is next to
>useless practice from the same kind of wilful carelessness that brought the
>world so many default/engineering/field service passwords/backdoors.

I doubt it'll make any difference, those who would read and follow the RFC on
this point won't be using insecure certs/keys anyway, and those who are using
them will ignore (or not even read to that point) the RFC.  I've heard this
sort of thing referred to in the past as "workgroup posturing", and that's
unfortunately what it'll be...

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.