> SSLv3 is a defacto, industry standard, devised by the best cryptanalyst > we have. It is represented only by an expired Internet Draft. TLS is a > committee effort. You be the judge.
That is unfair, misleading, and wrong. All IETF standards are committee efforts. And with all due respect to the SSL designers, "best cryptanalyst" seems an honor that (at least) Rubin, Bellovin, Blaze, Kelsey, Shamir, and their colleagues could all reasonably lay claim to. Some of them were involved in TLS. I'm surprised to see this post coming from you, Michael -- someone been tapping while you were out Starbucking or some such? :) /r$ -- Zolera Systems, Securing web services (XML, SOAP, Signatures, Encryption) http://www.zolera.com ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]