Michael van Elst <mlelstv%serpens.de@localhost> writes:
On Wed, Aug 21, 2019 at 08:12:11AM -0400, Greg Troxel wrote:
There is also talk of adding a NONE cipher back, and I hope we didn't do
that (but it seems highly highly unlikely we would have).
We added support for the NONE cipher. That is still secure in that it
guarantees proper authentication and integrity, just confidentiality
gets lost.
"secure" is a complicated word :-) I see your point about authentication
and integrity, but it breaks the property that if you use ssh then you
are sure there is no way to end up without encryption. (I get it that
with TOFU you aren't sure you are sending data to the right place, but I
see that as somewhat separate.)