ietf-openpgp
[Top] [All Lists]

Re: Do we need to secure our keyservers against kind of DoS Attacks

2009-02-02 14:24:11

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On Jan 31, 2009, at 2:54 PM, Christoph Anton Mitterer wrote:

* PGP Signed by an unverified key: 01/31/2009 at 02:54:48 PM

Hi.

I having the following issue on my OpenPGP "TODO" list for some very
long time now, and David just remembered me on it.

I do not understand either the problem you're trying to solve or the  
solution.

Let's start with a problem description.

I believe that the problem you're describing is that your connection  
to a keyserver is passing through some evil router that rewrites your  
connection. Am I right?

Why isn't the solution to this "use SSL/TLS"?

        Jon


-----BEGIN PGP SIGNATURE-----
Version: PGP Universal 2.6.3
Charset: US-ASCII

wj8DBQFJhzebsTedWZOD3gYRAq5YAJ9nzgbGAtYEbv6d0BnjfHV7kmchVACgkqWJ
XzLG73TvDATkidZFOnDgbdk=
=ytlY
-----END PGP SIGNATURE-----