> Yes, but then we are again at the point that weaker devices will be at a 
> disadvantage, and that we are burning CPU power for nothing.

If the choice is failure to connect because the server has to push off some 
load, versus a delayed connection...

> But I could be wrong. Do we actually have evidence of DoS via TLS?

Yes.  Here's one  
http://www.arbornetworks.com/asert/2012/04/ddos-attacks-on-ssl-something-old-something-new/

--  
Principal Security Engineer
Akamai Technologies, Cambridge, MA
IM: [email protected]; Twitter: RichSalz

_______________________________________________
Uta mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/uta

Reply via email to