RE: [Cfrg] Fwd: [saag] [Sam Hartman]draft-harris-ssh-arcfour-fixes-02: informational or proposed?

pgut001@cs.auckland.ac.nz (Peter Gutmann) Thu, 02 June 2005 07:47 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DdkQe-0005db-Ka; Thu, 02 Jun 2005 03:47:48 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DdkQd-0005dV-Jh for cfrg@megatron.ietf.org; Thu, 02 Jun 2005 03:47:47 -0400
Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA15142 for <cfrg@ietf.org>; Thu, 2 Jun 2005 03:47:42 -0400 (EDT)
Received: from mailhost.auckland.ac.nz ([130.216.190.13] helo=smtpc.itss.auckland.ac.nz) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DdkkY-0004sn-1f for cfrg@ietf.org; Thu, 02 Jun 2005 04:08:23 -0400
Received: from localhost (localhost.localdomain [127.0.0.1]) by smtpc.itss.auckland.ac.nz (Postfix) with ESMTP id 9264334B5A; Thu, 2 Jun 2005 19:47:30 +1200 (NZST)
Received: from smtpc.itss.auckland.ac.nz ([127.0.0.1]) by localhost (smtpc.itss.auckland.ac.nz [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 08500-04; Thu, 2 Jun 2005 19:47:30 +1200 (NZST)
Received: from iris.cs.auckland.ac.nz (iris.cs.auckland.ac.nz [130.216.33.152]) by smtpc.itss.auckland.ac.nz (Postfix) with ESMTP id 516F633F7B; Thu, 2 Jun 2005 19:47:30 +1200 (NZST)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by iris.cs.auckland.ac.nz (Postfix) with ESMTP id 4A69B37757; Thu, 2 Jun 2005 19:47:30 +1200 (NZST)
Received: from pgut001 by medusa01.cs.auckland.ac.nz with local (Exim 3.36 #1 (Debian)) id 1DdkQS-0005jQ-00; Thu, 02 Jun 2005 19:47:36 +1200
From: pgut001@cs.auckland.ac.nz
To: ggr@qualcomm.com, mcgrew@cisco.com, uri.blumenthal@intel.com
Subject: RE: [Cfrg] Fwd: [saag] [Sam Hartman]draft-harris-ssh-arcfour-fixes-02: informational or proposed?
In-Reply-To: <3DEC199BD7489643817ECA151F7C5929013C8E47@pysmsx401.amr.corp.intel.com>
Message-Id: <E1DdkQS-0005jQ-00@medusa01.cs.auckland.ac.nz>
Date: Thu, 02 Jun 2005 19:47:36 +1200
X-Virus-Scanned: by amavisd-new at mailhost.auckland.ac.nz
X-Spam-Score: 0.9 (/)
X-Scan-Signature: 7bac9cb154eb5790ae3b2913587a40de
Cc: cfrg@ietf.org
X-BeenThere: cfrg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:cfrg@ietf.org>
List-Help: <mailto:cfrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@ietf.org?subject=subscribe>
Sender: cfrg-bounces@ietf.org
Errors-To: cfrg-bounces@ietf.org

"Blumenthal, Uri" <uri.blumenthal@intel.com> writes:

>I support Greg's position.

<AOL>Me too</AOL>.  Or at best it should be published with a strong disclaimer
that it's only for legacy purposes and shouldn't be used in any new apps.  I
realise it's used in various IETF standards, but only for legacy reasons, the
weaknesses should really be addressed by dropping it, not with turd-polishing.

Peter.

_______________________________________________
Cfrg mailing list
Cfrg@ietf.org
https://www1.ietf.org/mailman/listinfo/cfrg