[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Some comments on JFK




In message <kjvgfoce7h.fsf@romeo.rtfm.com>, Eric Rescorla writes:
 >The draft says:
 >
 >   The Initiator bears the initial computational burden
 >   and must establish round-trip communication with the Responder
 >   before the latter is required to perform expensive operations.
 >
 >This text suggests that the fact that the initiator performs
 >the DH operation first protects against DoS. As far as I can
 >tell it does not.

Ambiguous language --- valid Initiators do perform computation before the
Responder, and that was the observation. This is not a mechanism for protecting
against DoS attacks.

The IPsec mailing list seems to be randomly dropping my messages (or delaying
them forever ?)
-Angelos




Follow-Ups: References: