|
|
Choosing A Webhost: |
Re: ZRTP, Key Continuity, and bump in the stack: msg#00255ietf.rtpsec
Craig Southeren <craigs@xxxxxxxxxxxxxxxxx> writes: >> The basis of this attack is that in a bump-in-the-stack impl., >> there's no mechanical way to verify that the identities at >> these two layers match. This allows a substitution attack between >> any two people who are in your authentication cache. The upshot >> is that bump-in-the-stack impls. aren't really safe... > >Accepting any legal ZID in the cache when negotiating a call is a very >naive approach. I think it's reasonable to for Alice to assume that Bob >will use the same ZID every time they talk. If the ZID changes, then >this should be confirmed by the user in the same way that a cert change >would be confirmed. But isn't it the case for pure bump-in-the-wire case that "If the ZID changes" can't be checked by the ZRTP code - the user has to verify it on every call. >I wasn't able to find any mention of this in the ZRTP draft - I think it >probably should be mentioned. Definitely! Though this does cause issues with the classic non-crypto-aware user reactions (i.e. click "Ok" on any random "is this ok?" requester, and if possible click "don't bother me with this again"). >To be extra safe you can use different ZIDs for every remote party as >described in 5.9 of the ZRTP draft. Does this help in the case of bump-in-the-wire? I don't think so... -- Randell Jesup, Worldgate (developers of the Ojo videophone), ex-Amiga OS team rjesup@xxxxxxxxx "The fetters imposed on liberty at home have ever been forged out of the weapons provided for defence against real, pretended, or imaginary dangers from abroad." - James Madison, 4th US president (1751-1836)
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | RTPSEC BoF agenda and slides, Dan Wing |
|---|---|
| Next by Date: | Re: ZRTP, Key Continuity, and bump in the stack, Randell Jesup |
| Previous by Thread: | Re: ZRTP, Key Continuity, and bump in the stack, Craig Southeren |
| Next by Thread: | Comments on zrtp-03: non-technical, Colin Perkins |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |