[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Some comments on JFK
In message <kjvgfoce7h.fsf@romeo.rtfm.com>, Eric Rescorla writes:
>The draft says:
>
> The Initiator bears the initial computational burden
> and must establish round-trip communication with the Responder
> before the latter is required to perform expensive operations.
>
>This text suggests that the fact that the initiator performs
>the DH operation first protects against DoS. As far as I can
>tell it does not.
Ambiguous language --- valid Initiators do perform computation before the
Responder, and that was the observation. This is not a mechanism for protecting
against DoS attacks.
The IPsec mailing list seems to be randomly dropping my messages (or delaying
them forever ?)
-Angelos
Follow-Ups:
References: