Re: [TLS] Proposal for hybrid solution using most of the ideas
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Proposal for hybrid solution using most of the ideas
Nasko Oskov wrote:
Session resumption is already secure since it uses existing crypto state as
part of the negotiation. There are no problems in that case.
I don't agree -- session resumption is orthogonal to renegotiation, at
least in my own code. A MITM could exploit that. This is one part of
RI that I agree with.
Mike
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.