5 Oct 2004 23:19
RE: FW: DISCUSS: draft-ietf-ipcdn-bpiplus-mib-14
Eduardo Cardona <e.cardona <at> CableLabs.com>
2004-10-05 21:19:40 GMT
2004-10-05 21:19:40 GMT
Thanks Steve, we will scope the text showing the lack of robustness for
targeted attacks as you pointed, or even removing it on favor or a more
encouraging text for stronger encryption.
Thanks
Eduardo
-----Original Message-----
From: Steven M. Bellovin [mailto:smb <at> research.att.com]
Sent: Tuesday, October 05, 2004 12:49 PM
To: Jean-Francois Mule
Cc: Russ Housley; bwijnen <at> lucent.com; ipcdn <at> ietf.org; Eduardo Cardona;
Richard Woundy <at> Comcast; Eric Rosenfeld; Oscar Marcia; Greg White
Subject: Re: [ipcdn] FW: DISCUSS: draft-ietf-ipcdn-bpiplus-mib-14
That address most of my concerns. But I also said this:
The Security Considerations section says
The time to crack DES could be additionally
mitigated by a compromised value for the TEK lifetime and Grace
Time
(up to a minimum of 30 minutes for the TEK lifetime, see
Appendix A [1]).
That's only partially correct. These keys are confidentiality keys;
they're still valuable even after they're no longer in active use,
because they can be used to decrypt old traffic. (By contrast, old
authentication keys are useless to an attacker.)
(Continue reading)
RSS Feed