[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Confirm decision on identity handling.



Michael Thomas <mat@cisco.com> writes:

> Eric Rescorla writes:
>  > Given that you're the one suggesting that we ought to ignore
>  > known possible active attacks [...]
> 
> Live With != Ignore. I'm interested in raising the
> bar for security, not boiling the ocean.
The belief that active attacks are important is part of the IPsec
threat model. IPsec is riddled with features that assume it to be the
case. If we were going to design a system that doesn't provide
protection against those attacks, we'd design an entirely different
system.


> This
> entire exchange is pretty much illustrative of why
> security protocols are deployed so few and far
> between.
And yet, strangely, the most widely deployed security protocol
in the world depends entirely on a universal PKI. 

-Ekr

-- 
[Eric Rescorla                                   ekr@rtfm.com]
                http://www.rtfm.com/