Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-10-09 Thread Hao, Feng
uot;Downgrade protection: The cryptographic parameters should be the >> same on both sides and should be the same as if the peers had >>been >> communicating in the absence of an attack" >> >> (I have not looked at what the definitions in [BBFGKZ16] say). &g

Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-10-05 Thread Christopher Wood
ohn > > -Original Message- > From: TLS on behalf of "Hao, Feng" > > Date: Tuesday, 24 September 2019 at 16:09 > To: Mohit Sethi M , > "Owen Friel (ofriel)" , Jonathan Hoyland > > Cc: "TLS@ietf.org

Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-09-24 Thread Hao, Feng
t looked at what the definitions in [BBFGKZ16] say). Cheers, John -Original Message- From: TLS on behalf of "Hao, Feng" Date: Tuesday, 24 September 2019 at 16:09 To: Mohit Sethi M , "Owen Friel (ofriel)" , Jonathan Hoyland

Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-09-24 Thread Viktor Dukhovni
> On Sep 23, 2019, at 1:49 PM, Mohit Sethi M > wrote: > > Hi all, > > On the topic of external PSKs in TLS 1.3, I found a publication on the > Selfie attack: https://eprint.iacr.org/2019/347 If I not missing something, eeels like simple misconfiguration. How is this different from, say, us

Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-09-24 Thread John Mattsson
Sethi M , "Owen Friel (ofriel)" , Jonathan Hoyland Cc: "TLS@ietf.org" Subject: Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs On 23/09/2019, 18:50, "TLS on behalf of Mohit Sethi M" wrote: Hi all,

Re: [TLS] Selfie attack was Re: Distinguishing between external/resumption PSKs

2019-09-24 Thread Hao, Feng
On 23/09/2019, 18:50, "TLS on behalf of Mohit Sethi M" wrote: Hi all, On the topic of external PSKs in TLS 1.3, I found a publication on the Selfie attack: https://eprint.iacr.org/2019/347 Perhaps this was already discussed on the list. I thought that sharing it