[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC2409



I don't understand what the attack is, I'm sorry.  It appears
that both the Initiator and Responder believe that they
are talking to the cheater, so what is failure?  If the
Initiator and Cheater are collaborators, then can share
signing keys as easily as decryption keys, so the "fix"
doesn't make sense to me, either.

It's possible that there is a flaw, given that the two
sides don't ever prove that they can compute the shared key,
but I don't exactly see what's wrong.  Please explain.


Hilarie