Re: [TLS] draft-rescorla-tls-renegotiate and MITM resistance
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] draft-rescorla-tls-renegotiate and MITM resistance



Marsh Ray wrote:
> Yair Elharrar wrote:
>> In addition, until such time that all clients in the world start
>> supporting this extension (e.g. kiosks in airports), servers will
>> have to support backward compatibility.
> 
> It will be a trade-off for each server admin to weigh and decide their
> policy. I suspect many admins will prefer not to allow insecure
> connections from unpatched airport kiosks.

To prevent this attack, they don't have to disallow connections, only
renegotiations in which the extension is not used.

-- 
David-Sarah Hopwood  ⚥  http://davidsarah.livejournal.com

Attachment: signature.asc
Description: OpenPGP digital signature


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.