logo       

Re: Security Considerations: msg#00163

network.syndication.atom.protocol

Subject: Re: Security Considerations


On 8/10/06, Eric Rescorla
<ekr-wquOhMu7Nthx1G/IGiyUYVaTQe2KTcn/@public.gmane.org> wrote:

As previously noted, not my problem.

I don't see how that POV will result in a productive security analysis.

I don't agree with that analysis. The attack you're talking about
is active, but Basic has passive attacks.

But I'm not advocating Basic. There are more choices for implementers
than there are for IETF specs.

Once the user disconnects and the server times out his
session, the attacker can't reconnect.

I don't think we're talking about the same protocol or implementation concerns.

--

Robert Sayre

"I would have written a shorter letter, but I did not have the time."




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise