Changeset 2489 for wg_materials/ietf88


Ignore:
Timestamp:
12/11/13 03:44:27 (9 years ago)
Author:
mnot@…
Message:

small edit to minutes suggested by Eliot

File:
1 edited

Legend:

Unmodified
Added
Removed
  • wg_materials/ietf88/minutes.txt

    r2478 r2489  
    382382EL: Concerned this introduces a new form of MitM.  If yu have this header, that now says you can use relaxed, a MITM can insert the header or replace a 301 with a header, and the server thinks it has an encrypted tab but is really sending data through the MITM.
    383383
    384 EL: Why would the attacker not just proxy HTTP, and I'm just saying this is another avenue.  I'm also not sure we understand the consequences of adding a new property about saying "don't bother to verify the certificate" and confusion about unathenticated encryption versus authenticated encryption.
     384EL: Why would the attacker not just proxy HTTP, and I'm just saying this is another avenue.  I'm also not sure we understand the consequences of adding a new primative about saying "don't bother to verify the certificate" and confusion about unathenticated encryption versus authenticated encryption.
    385385
    386386Salvatore ??: I am worried we are putting to many things together, and changing things on the fly.  It might be too much to manage.
Note: See TracChangeset for help on using the changeset viewer.