Re: [TLS] Issue 49: Finished.verify length
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Issue 49: Finished.verify length



At Fri, 14 Sep 2007 11:08:53 +0200,
Bodo Moeller wrote:
> > As I recall, the truncation was intended to *increase* security,
> > because it leaked less information about the MS to an active
> > attacker.
> 
> I am not convinced that this is a good reason.  Assume that the
> adversary tricks the parties into using weak encryption with some
> non-ephemeral key exchange, say.  Then not only the verify_data will
> be potentially visible to the adversary, but also the record-layer MAC
> will be exposed, which can be a lot of additional data (both depending
> on the master secret).

Me neither, BTW. I just seem to recall that that was the reason :)

-Ekr

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.