IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Core draft last call update.



On Wed, Mar 13, 2002 at 05:52:19AM +0000, David Wagner wrote:
> Markus Friedl  wrote:
> I admit I don't understand.  I come from a philosophy that says
> you disclose what you know about the security properties of the
> protocol, both positive and negative: truth in advertising.  If
> the decision is that fixing this weakness is too costly at present,
> that's one thing; avoiding all mention of it is another.  What's
> gained by hiding the facts from implementors and readers of the RFC?
> Can you help me understand the rationale behind such a stance?

Oops, this is not my intention:  I think it's better to offer
alternatives in the RFC.  If we want to offer alternative
reaching consens on OFB and CFB is faster, especially since many
installations/implementations already support these.



Home | Main Index | Thread Index | Old Index