Thanks for the review, Peter!
I would be interested in hearing an answer at least with regards to the
following items:
Section 7.2: Is the "Delete" operation meant to be atomic? Should that be
specified in that section?
Section 9.7: this section discusses how the "transport protocol" provides
connection protection services and then says that therefore a
man-in-the-middle attack is possible. If that's the case, then the
"transport protocol" is not (adequately) providing connection protection.
And without connection protection, a man-in-the-middle attack would of
course be possible, so saying that because there is connection protection, a
man-in-the-middle attack is therefore possible seems misleading.
In both cases I too was left wondering what the text actually meant.
Jari
signature.asc
Description: Message signed with OpenPGP using GPGMail