Re: [TLS] NIST TLS recomendations (PKCS#1 encryption attacks)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] NIST TLS recomendations (PKCS#1 encryption attacks)



Martin Rex <martin.rex at sap.com> writes:

>Completely hiding the decryption failure from the local caller creates a
>serious supportablility issue, so please be more careful with the
>recommendation.

Another thing that should really be mentioned in the text (which I've pointed
out before) is that the requirement to continue makes for a marvellous DoS
attack, just blindly send a string of TLS handshake packets with a garbage
value for the RSA-encrypted data and the server has to go through the entire
rest of the handshake.  In some situations (e.g. low-powered devices) this
"defensive" measure may be an own-goal.

Peter.

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.