IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: issues



Darren J Moffat writes:
> Mika Kojo wrote:
> 
> > Perhaps a better solution is to give the user some indication of the
> > security level achieved in a particular session. Of course, it is
> > difficult to measure security exactly, but this is only required to be
> > a rough approximation (say, `very secure` > 2^128, `secure' > 2^80,
> > `broken' <= 2^80, when measured in elementary operations).
> 
> I see it as an implmentation issue, unless you are requesting
> that some definition of security quality is added to the protocol.

You are right, it is an implementation issue. It is possible to give
some formulas for computing the "security level", but ultimately such
formulas would only have informational value.

Best regards,
Mika Kojo
SSH Communications Security Corp



Home | Main Index | Thread Index | Old Index