Yo Hal!

On Mon, 14 Jan 2019 12:19:09 -0800
Hal Murray via devel <devel@ntpsec.org> wrote:

> When the NTP server is returning new cookies to the client, they are
> encrypted so that a spy can't track the client if it moves to a new
> IP Address before it uses the cookie.

I see nothing in the Proposed RFC that binds a cookie to an IP.  Good
thing, it is a bad idea.

RGDS
GARY
---------------------------------------------------------------------------
Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703
        g...@rellim.com  Tel:+1 541 382 8588

            Veritas liberabit vos. -- Quid est veritas?
    "If you can’t measure it, you can’t improve it." - Lord Kelvin

Attachment: pgpxzGFtsY1Q6.pgp
Description: OpenPGP digital signature

_______________________________________________
devel mailing list
devel@ntpsec.org
http://lists.ntpsec.org/mailman/listinfo/devel

Reply via email to