gnutls-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Another renegotiation patch


From: Steve Dispensa
Subject: Re: Another renegotiation patch
Date: Fri, 22 Jan 2010 14:57:49 -0600
User-agent: Microsoft-Entourage/12.20.0.090605



On 1/21/10 2:42 PM, "Nikos Mavrogiannopoulos" <address@hidden> wrote:

> Steve Dispensa wrote:
>> Here is another patch that fixes an interoperability problem with safe
>> renegotiation and resumption. In copying forward the safe renegotiation
>> state across resumptions, I got a little carried away and copied too much
>> data (new connections should start with empty RI data).
> 
> I was thinking about the safe renegotiation case. Currently with the
> defaults the client behavior is to drop the connection to servers that
> do not advertise safe renegotiation... This is quite an inconvenience.
> How do you think of instead of failing disabling renegotiation for this
> session? 

The client can't tell when the attacker is renegotiating. If the client
doesn't want to, e.g., tweet his password in clear text, he has to drop the
connection.

The whole problem is that to the attacker and to one peer, it looks like a
renego, but to the other peer, it looks entirely normal.

 -Steve





reply via email to

[Prev in Thread] Current Thread [Next in Thread]