Re: [TLS] Issue 49: Finished.verify length
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Issue 49: Finished.verify length
At Fri, 14 Sep 2007 11:08:53 +0200,
Bodo Moeller wrote:
> > As I recall, the truncation was intended to *increase* security,
> > because it leaked less information about the MS to an active
> > attacker.
>
> I am not convinced that this is a good reason. Assume that the
> adversary tricks the parties into using weak encryption with some
> non-ephemeral key exchange, say. Then not only the verify_data will
> be potentially visible to the adversary, but also the record-layer MAC
> will be exposed, which can be a lot of additional data (both depending
> on the master secret).
Me neither, BTW. I just seem to recall that that was the reason :)
-Ekr
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.