ietf
[Top] [All Lists]

Re: Protocol Design Pattern (was Re: [saag] Last Call: <draft-dukhovni-opportunistic-security-01.txt>)

2014-08-19 08:11:25
Hi Nico,

On 8/18/14, 5:35 PM, Nico Williams wrote:

- Follow RFCs as strict as possible to defeat fingerprinting attacks
Agreed, but again: too generic.

- If a connection is one-sided authenticated (eg like TLS) ensure your
  protocol is okay with a role-reversal (eg if it needs to authenticate
  the end that was anonymous)
Ditto.

Are you saying you want an example of one-sided authentication where
role-reversal #FAILs?

Eliot


Attachment: signature.asc
Description: OpenPGP digital signature

<Prev in Thread] Current Thread [Next in Thread>