Re: removing keygen from HTML
Reto Gmür <[email protected]> Tue, 31 May 2016 13:40:04 +0200
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <1464694804.2494928.623494785.69396274@webmail.messagingengine.com> |
This is a multi-part message in MIME format. --_----------=_146469480424949280 Content-Transfer-Encoding: 7bit Content-Type: text/plain On Tue, 31 May 2016, at 10:04, Harry Halpin wrote: > I do not know anyone from the cryptographic or security community that > would support keeping <keygen>. Indeed, the default response from the > security/crypto community would be to drop <keygen> due to legacy > usage of MD5 and violation of security boundaries (SOP). That would also be my response if I was employed by the NSA and wanted to prevent technologies that allow user controlled strong cryptography and decentralized networks of trust (as enabled by webId). Cheers, Reto --_----------=_146469480424949280 Content-Transfer-Encoding: 7bit Content-Type: text/html <!DOCTYPE html> <html> <head> <title></title> </head> <body><div>On Tue, 31 May 2016, at 10:04, Harry Halpin wrote:<br></div> <blockquote type="cite"><div dir="ltr"><div><div><div>I do not know anyone from the cryptographic or security community that would support keeping <keygen>. Indeed, the default response from the security/crypto community would be to drop <keygen> due to legacy usage of MD5 and violation of security boundaries (SOP). <br></div> </div> </div> </div> </blockquote><div>That would also be my response if I was employed by the NSA and wanted to prevent technologies that allow user controlled strong cryptography and decentralized networks of trust (as enabled by webId).<br></div> <div> <br></div> <div>Cheers,<br></div> <div>Reto<br></div> <div id="sig46204098"><div class="signature"> </div> </div> <div> </div> </body> </html> --_----------=_146469480424949280--