Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)

"Roland Dobbins" <rdobbins@arbor.net> Mon, 17 July 2017 17:06 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 72D6D1300CE for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 10:06:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level:
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9E8OHAmIjET3 for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 10:06:39 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0123.outbound.protection.outlook.com [104.47.42.123]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5DDF7131B3E for <tls@ietf.org>; Mon, 17 Jul 2017 10:06:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=GRMflo5SzS0T7zrflt5iyvGwPcKdCMK/qJ4b3ar3AGo=; b=UTSDtVxwwFLK3H21/3rAkZwk+7pP8Z3dmR8CXORUiOa2ZPXo2GyxXoK8rj1xUQT8zaQZwqp+egim18DKfENrzCdStYPuq60XRvhJJ3my+8PRx8ai0S9z7I+1nkJDDbr+pdl1B6KmVP2yuf57ojWoR68jFcAcZjui3I0e8baH7cU=
Authentication-Results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=arbor.net;
Received: from [172.16.1.3] (88.208.89.131) by BN3PR0101MB1026.prod.exchangelabs.com (10.160.182.155) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 17:06:32 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: Watson Ladd <watsonbladd@gmail.com>
Cc: Simon Friedberger <simon.tls@a-oben.org>, tls@ietf.org
Date: Mon, 17 Jul 2017 19:06:21 +0200
Message-ID: <7B8FCD1C-D6F2-49E0-A88E-053CB8ABE279@arbor.net>
In-Reply-To: <88AD564A-B299-44EB-A825-D20717119AC8@arbor.net>
References: <CABkgnnU8ho7OZpeF=BfEZWYkt1=3ULjny8hcwvp3nnaCBtbbhQ@mail.gmail.com> <2A9492F7-B5C5-49E5-A663-8255C968978D@arbor.net> <CABkgnnX7w0+iH=uV7LRKnsVokVWpCrF1ZpTNhSXsnZaStJw2cQ@mail.gmail.com> <FDDB46BC-876C-49FC-9DAE-05C61BB5EFC9@vigilsec.com> <9C81BE7B-7C21-4504-B60D-96BA95C3D2FD@arbor.net> <CAEa9xj55jzch-v0mysbRSryNM0Y7Bdtevmrc3+FVxMO8EP5zWA@mail.gmail.com> <CC3CE5F8-C8C2-4A70-829D-483E26D20733@arbor.net> <CAEa9xj5eR6b_+CsSDArMWWr-u8hx5B81kDVEMEX8sgfUeMUS8g@mail.gmail.com> <C3B01C35-E3A2-4A8B-9DD7-D6E4153ED39F@arbor.net> <CAEa9xj6p0y9ZzxLJvtv9GDzzfs5s13nnLqm=4_fNDPGV+=Od8Q@mail.gmail.com> <BE4E8E4A-51FC-4211-A16F-EBA8B3F01757@arbor.net> <CAEa9xj7sVcGAR03f3pWsK7giFqmu7GRHN4gqh9Nb6uEAOM88Yw@mail.gmail.com> <637C97B3-DA63-4F61-8EB5-D938136D520C@arbor.net> <dfc93b70-0fa4-6cac-8c3d-5f2ff771f85d@a-oben.org> <64A2BAB5-5EAC-4608-9BF4-856CA0859042@arbor.net> <CACsn0cnXv_f_o4NEMMsYW7KQ8UqyEzhyYSAqyZpfsc4ddOr=eA@mail.gmail.com> <CACsn0ckBT29pqdrUk7DfcscmEmG8zoVn119gY+Y73FEuheJGTg@mail.gmail.com> <CACsn0cmmrGd1Q4-GmbJ2VNXUUgKyX18_MsBQmuA2e86bPcLxMQ@mail.gmail.com> <88AD564A-B299-44EB-A825-D20717119AC8@arbor.net>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [88.208.89.131]
X-ClientProxiedBy: DB6PR05CA0008.eurprd05.prod.outlook.com (10.170.218.21) To BN3PR0101MB1026.prod.exchangelabs.com (10.160.182.155)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 26985b9e-d5a1-4b81-85c8-08d4cd362c9d
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(300000503095)(300135400095)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:BN3PR0101MB1026;
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 3:Ov5m1ExibzAS/UqpaVfgkGqBm/24tspvIYLlxojJzovVP3pSMbfK1IAiRPeDsCjX4ufY6AA15M8/SwXenxGYbzOzuqoTrq4/sJleVttUp1dXwHabCzpEt2Z93xAjkzfGOqDHeADp53OPD9WhnE6B7PfhkCY2Jwq70ffUZFZqyM7Mwj2OUdCLiYvxqLCXZ9r7sXaeMdwwV4ZDTSl96eu+MM2oiTYL2JWVbHrqywQRCJvCBRKS/K/xD0RRel92gLBwXlb0KBmIHZoWvXzj0HIEwFCsp30GKBRhCd72s3lSwymOftpAGfKHWJ3rMBbD1UREn9jProD8uRuRYQBXzVHqpPd9hQJM+Iqj57JvDKfA+P9bR35kbk88xTqlpL5sLjwb+8tmxQ8iCemUDMpcajnwdXfF/1B+B+T+kJxYBR9RMrbtQUoMwZBcw7iNUU7t9uWolDiQyINmQabRIt/Nj8Uxghith3r668W4oqeI7r/DmZawiw3zGK2HY/6Wab3S2TmpRwo7enyvn/sSoJQrLzqpFLpcBB0faDq7LstOrhX1mFJJfcBi6DMvxbqdkkhu11qCsWqxiyvfrlYoUO/6UuRpD+nc6WD3d0rRlVmnVM5xEMm+jAx8b9W3rc/5L4pzbq19mfqHw00n1Y/uwDqMUP34zBylrIkW7zkPmOoGkQO24w3fZWXU+P3Srw+nn+epEtOxPekLa98jZon8mJyLnXwWpCr8bR2t8Ng1QpvIhe9GQp4=
X-MS-TrafficTypeDiagnostic: BN3PR0101MB1026:
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 25:UHGQaeXG27Gs17xC1CYbA/a3HVxgx2xFhqQlpNXszvCJpqGrn/ANayZrS3qgAPkJix7I1TXjJymA6CfITOvWIINOg5UOADumTkwq8n2+Hg9NoeQ0dR4y967vxA+nhLx/My2G9k2HjLOjmDXSeYaI5KMTrXrcqvxDPwPwMW2CwRNMJ85IA/iqiq9duDkaGdS0VHoJZfJZ6ZKweRL9Rz0U5P/tQaTAYfW5M8XwzXZeSEhagD7fdUjAO6+emWitVfgHKzSTrQHfVqJeU2Ig3oDO+uMJw2EdRzafrfmSj5lkWcFsGSMz7HNySJk/IpqozkIQtlcpQvoFssFizUkivFIFLOqHWCQI4E0qV2+S5kqkXHtuhKSHdFlZxxGPEhyz7tZ//CSGrZLuOL/kkYpG0cMdrddzqJqAlL/GQi8AeFtvsGXg4NkejYWiLnektzatmMKkwzvcg15ikblXMoac5Gdq4BphH7HzoodzpifX4DRXwuUuAsIQ85V1FQdEDWWVn9tzz53dH1jrdAovqJMHZ0X3yGozUuEyl6ok5nQJdPzNH2gJf9kpgfD4ChrmzJgwT2pj9shNi3/c25DzHl8lSLnNTt0h1w7Ttwpv5JZPZkPIg4fi8O864tD2zc6YDnxFZTmonTAMgbMJgP3MZ1usKqEXSkZnQJVxzdXCPfBlQriNUTdXcH1Apg9ZiXrkrpcQxdCG+/lAM1CqnAx2gqGB62uzmFsecRpfbPebAIGM4kPulw5spsDwvLilGoNxuu0ckyg+mPZ5zStN0gASqbxfFST0Rysf7RlruItpoxGHyZgO/7LNqLeN7YcvG5N6cueAHGhyENXIOeC7Bznyb235zzkQcFLXNmmXy1QucsgmEz/nxTRb0RKiybtKL6AmUCB3ybK4bJutfN6E9M9Vz2sAgfcWt+NaRfiLo3nwHyHIHSuQgk0=
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 31:FYN1to+1fKQ9vQoM1gdCR7bGEwAesH+EjgcRdz0zQiFaK/Gd/Xe5ej4yX9YfRTnwSm8AvzEopSI9EEexpsadz9+SJ47v90MTkrI8VTah2q0/lTvJmDv7ouC93UVn94+gnXM2yzy/fSJUmqeVSwaGnrdzafdOAeg3KsNgAYfKSwwJ/hHR8HmlzKLi5g1n5h9uyuLzCALosWYc5mYUVYaQ5D1q985OhRIvwrBS1eGqPfq+EL2OcaB7Ed6O7Aqacv3PyRkzWZUHQ3CHf0ONYmCbjAfVPUFjXjrJVfJt7XU5n6VQE0SO4eqKyWQSgcNGyJM+I2zJ2/zjzIcvy5Ecm4W4cKyfz9mxIDiJA92TvQozaE25rWICGFZQSbMUtW/rS8FAv43I819ckAOcm157IVgsI9S2aIPo/P98ZKwrOEZeWkVjY5rhl0I1i3cWoNaMu2AfBiqlhCigq3sZ9Yvjtguavng3m/JcxHxpYoj/b0K60zTipIXBi3sS/ng6OBGctZD2WD2NKw18Py2uqxfowWej/g/Xi8jCxr6gxvTSUUqEPJ9ozGL8AK3idFgBGTEJej87UdFUwEwzcupdNaKR3VJ6AWpr9DGroWQqftYsCZczW/NboAH2SHMIHYJNgpz96JsXVHVVDCoqNL1YaLVtEk6S7aLNj84XvHzoRCZfYgks3HeWnrNMc7iNdhBHVWUrKCL5
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 20:1U3+6A0hTM2z/DCXiQrXI5gkUsc9luaBCDj3BUayWXTVfdDoIsadGve4b2/Nud+tIbbyZqKqkVmfPlgYNull3RJxyxV7uOhoc6DMYNAdkS0y8VUEoNebY6e+iWOt7DpS6amTeieuGbOcEUV86IjxCxLnNFTLsa/i1dlS11veq0MsnFCFJRN455adVaHzmH6LKCwsEoA3P4a4OTnMgpOKf5yZdToI1NzZSXOo70I0M66eErpYR9yjh4AnT4E1mHBQZdF79taj6wsAvS3rRQTdiIEd6hcxnA2XCltaH8+gFqDT9NP9rjSjftVpH2E8obkod0W80kYHbS1DUA/qCBEuCN5XQCmlmuzNr1tFRkVPckCiOwKAQ7ZxC5xHpAWpJOXq+RxAoHZv4qIDYSf38zcP6+TMyOPJyxlrYzmkrQ0fxUQQKx2wQCo+qvAUMckANiQYV0Q92vGy8uv2I1cNKJtMh3DhmuFZeGn/JfdgSF+4Mp5cFzCyudd5WTkH5lA2NT4a
X-Exchange-Antispam-Report-Test: UriScan:(236129657087228);
X-Microsoft-Antispam-PRVS: <BN3PR0101MB1026F8B760140DD58611DB6DCAA00@BN3PR0101MB1026.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(2017060910075)(93006095)(93001095)(10201501046)(3002001)(100000703101)(100105400095)(6041248)(20161123564025)(20161123562025)(20161123555025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:BN3PR0101MB1026; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:BN3PR0101MB1026;
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 4:1jBpMOy91lfVrIRswq2OlXHPlXmV11i8uv3DekQ7Qg95GKqj8uApsGYETFQP4WAOEg+xhxigNQbWAVq97cyhlgZSCh8Djk9NS2mVXwrnYDnsPbIjE73TEFWmbQlz7oXZ5Evlj311ckWsLzSKYSsAJ9B4hxnl9huccvE8lVHU4gOH5sKTxSyCuAgXcfVAiSXK+2beh20wJ/VYiZlFPzqRE+Au0Ti5Qv7uTg/xR1Tw34zeK03wpEF6mVRvS+Xn5aD87UiCJRG1XauhWwfrXjygEFNqn/jcouikAbj3HhGIB7YcYZtjix3w+/yHocR5M9YaOrMdeszYDXre4rN68JpXSwmE3mIhGj3BDb9/OzkmCWBrrxieO8ZC6zUel7y5n+mWFProRSNL1tj5ZW2GCkAEzhRDiTgYCdl5H7rGQVntrK4vl7WIfMlNnDoIzNc25yfKBoGkSg7Qvh6fZaxL+rd2+hlyM6a+GP4XP9OqoUtdrWDHcUH6/O1lE6ZiLw/mnzta8XmOfOc4GrcfSXnjk79CEmUEUYJ+raMNZQ4Czz62ct5PlU/GiSU20/sQE19yzoz9uptqC+vUu96JK3w/muwqQuujTef84AIepHAJ/fInsB99R08m9+cbQkWY2GeDvGPUPezZC+WWG/oEgroxA71b5+DfhBJF0hPJ2oRll/ywQuBmfnLXX7f3A7r8jF7I1OWOeCRblfMc8drsYz+pdXTPwjWYKLRx/CCqLWvGRo7+oX8PNFve08Xf0MD3bRDVnbOlWHMeaCLuOd+NabFjDuiBpRZzx/EUa727aiWEfN/9esEBpwzUSSYGUEwVNguSqjEzNFqaSWrsTUefgzJ1ZS+V9gLRXHAZi3F9KqECR0wq7rjA+IvMBpgRIeU5K7qTo7aZUicMA6onizw4z/FIbIIEezJ+/XYYoYHbOtM+kRk9/CdzHxSiNkzGrjEWsV9OpQtkagc3XTYPz0DNf1dcuHm4WAOVOAebmqsBb75hh/aLAsW862kT/9EwBG5jknVtEPSW53KE0Zu5JLiFh2aR4+WWqYSIgnZ8oFWGxLbFbdvN8Tfo7k1KdOWF5+qTM6K8gjlcTfewKGHsJ7KmrhBmA7oc+8Dew/3ndvU8o4LhOIHNG3euXoi8o2nlnSq/Xu9UzOnAyLlVzcQk8g6aXZPSiVDEFWwppYBzXTV38SD3oGovii7+vAqNPh+A115oZlSdTs6o
X-Forefront-PRVS: 0371762FE7
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(7370300001)(6049001)(6009001)(39840400002)(39410400002)(39450400003)(39850400002)(39400400002)(24454002)(5660300001)(93886004)(229853002)(38730400002)(6246003)(50226002)(7736002)(478600001)(90366009)(6116002)(3846002)(2950100002)(6916009)(6666003)(53936002)(50986999)(189998001)(4326008)(25786009)(83716003)(76176999)(558084003)(53546010)(86362001)(110136004)(82746002)(77096006)(5003940100001)(66066001)(33656002)(305945005)(47776003)(50466002)(36756003)(6486002)(1411001)(2906002)(8676002)(230783001)(81166006)(42186005)(7350300001); DIR:OUT; SFP:1102; SCL:1; SRVR:BN3PR0101MB1026; H:[172.16.1.3]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 23:GMZFibmNWbQpZ/nuxABi7IFRGpeEA2hzCxLoQTigW0pDcfyaljaGHTNmVez50iZel1mS+BQicmQnwUmQ0F9wQ6Chw7MPT4wNwgGUW+qvIw7gRYNzPPFNe4KegV4lfz0U+hUKe1EPNu0H6ppBALz65fqyemBZono6R9omzZyyemTc4TDW1Mz7XL0016M15vQ1jG8jA8v9xOeI9wQ5zUpaq0j+Au9jOC2NkDOC+6xpppIHDywjxAPJYaNs2c3mm16ozkpEbDOTsD42wDFZjCl23RjZCTFoG6CfYBI4l+XNNoFTy/kQ3q56GmRrK02iEaWX3PrEBkypaKZjTlk2cnYecdHOcPUHR2krSjjfZMziARK1XPFy0LOH1HAPAm/7rrtZLjmTfZJWVvVotWPGcpBXKNq75SknC/iLRFUSr1qTb2C4RQ94Ky2qGCBivf6QGB1tWv+N0a/lFR3VdTG6fU9d2AYgukgYOBicvFl7Teod8dU0fq0PKLfoVwnI5jqZRmo5ssYGX2GLlt4Jdb4Zccmai5tG9U9xV43agdeeHAlBWkaDY91YVo/arsl9TknZvqv7jchY6d5pHOyFCF8eGaJ1S6RhqfSs2W4GUr4EMfVzqY/UqqYX7JSnm1/c4wXtT81EZGcR73F8sqb4VWRTvqB4h6R+Z5uQyy0xgznpNc3utRvZdls5Kkbf85zWQCToM5FIdsXoYVSnHrYb5MnnhdHcOoRQFX3V8RTdg1IPQWY3htotMTMlhKT9uA0P1fmwQUdJAmvgyOb0Uapdu+Hd5eY5mGt9kXS9c+2QaFMhoUz2cFw5QwTGIG4AgVvoug3jxIQt5fRiLeN//CWaEuXWE3/jD8ltFSkACAk+qcgRQHW/ZqFcPdWZQOpDtbGyOTIm1V1UdezTJeqOTVwc38ZnHIil/0nhgspHS8vKly6KJRIbgUJPmyFkeKSty44SkjLVDNeLKx2tLEntJUw8MY0fLzl0D+p3Uzi/KM382pJeBDvgbtvt3hJOvbT0XPbAenCe8dh97Y0sQrTq24FDNJYOREV4nQqyB4MDO4KgKJGN8DeXoXQ5IKIZD0AVO1v6ESCV12FiHqb0KgPxPOddk/tEvU4aVRH5yaz75vrsBE8nlF3VmPwQmtu1RvGqjMUE3KvJi1XABWXTd6yhXKDAmeJB9KwABmcAgh7UhrGsqsOXepqo0b1RDGJ5/4nKiiUFKosWeiRp5EaHurZr49HepQO1wNzLRxxoYHs2YuZktj8/1FaWfz22M/qWq5FvlQwKZ+t4AfmGEFZTLmj4jBYnB7IniRoHaA==
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 6:9SHceTGg81ZRoY/O7yz6CPbPnhq6REkYN4xDpciy3O4dOrrFFZBz7XjT7X+UyRt1fpsgO5KtXBhp3Le8+27YHsJmetjYz9RoNexa17k7XoSLEBANrlwIra0n0h7tufLj1K/xfUk0EWUb44FVG07NZJz2o/obf6FnB+tA0EqcmYf3Qr9zsRN7+7bSW3jIv6BxuYpXaEhy6U1zKUhhaJJ3uWU9q9kAarYyf9R8pvJkTGHEiKlXlpZu62kJfGHESSUepA0edWbtsUPuU4nDa3R5ujs4oHMydYlcV5P5mPaLHqLULhR3YQsOtDOlPK/eD2z57pxiWkowcqoziZHXvynj5R1Nwm0YZ2HtYZgm29KPEiDMupP9/tqEJzmlB5soP9woUT8XG57d/DNP48UB02t5zTyR2zjfwygBnmhmZgslAIJ8/pgEkxibfTmRcncIEY5SlY27EP6okOiXn/yr5EV3dyt1HYXu/ZYkybncvBPjJVlgh7BdJd+fSoyz3OjTAFaHIwDRmOEps6L3v9WcBYTvJGU2JIPs++X4wOjUfqrWVwu6Cl77pwBsFshw0NeB24Zk2Y57fZbivEt0AvxkqTeeo+J0dDSjj6SqAA6P93No5sAw8kN0n+dH2PIlmsZBt7V60xhr6wds8VGwkVLZYKZOkZcFUt4zjYhMaxLEtRzcyLd+SY4TSHrAf+pSDdWHIJgfjWRjEpT79rM6aLmV89qApigTFidU84QyXiNOGIiPtPrEzHEWBs8ov6Hx99BOpS9fR18rp5eUK+8G7ZvsmM5iOfyfL9kIcuqxAQtS5Gnl5EIvYr4Iegz+sHqwaNJp2ciKiMngRj3Nuh0XiiYMxcw451DZqUEQjwgldVvUW9kOMOaITwZGXruG8jf++TBjP2Bu44iDxpa4sDuRxas+eZXCH73YAJ6iF/hGNJonNb/9wx+xM6buW2Fba0nJkHTzUTDLKW+cq1yd+al42/Zh0fz1Qp+EarPjxk75UC7CvFqcJqE=
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 5:p0C+7qLRvjcxxJlPB0tYkD8O8ZM/8AOVJE8LXu4JlUriEPgsCFbHZmQZSslkndfFM4Y4oQNIiycVRPx7OIKi7H4zFrKmRKSoZHI4uPuPkaL69plPhFZlbo77s3R6tf6hxrJzvUXES4Icue056Uq+Ajw4pe+B4qzAW7ESBznFjR3O0okN7ABvxoo0BAJT4WhxQ8oyP+HxH+AIeapBuihjhaJz9esyxqGw5R0md7Vy5wf3S6jytvJ7P9ga6dRb0uGbiyscEd5s4qqrVhFjE72UigY2xPEKhkvDft/1MBI0oMtjlFK7mZYxPn/2pAgPnBrfU7TKeRUfmot80f3Qrgsg9jNDJtpfPAPn/GCfZBCK0NyvsVWOfpOATCXVFnFTY1ANrmAUmCi0Ju1vjJ5SM76rNmvUiRmGeuJrWSL+ha2fpz9moH90ZV8FaPoB/jbIv2VM6C9ckVkHtnYtgxIe++LqnGId04VS5jbrMbKSAoSa56hHIkYIUQM6bUmBZDVhsVAW; 24:sB8gKRh+47AcmVL3k1mViTBhRalSwCe44Rnewxyl1wQ1Mal+Ed1YCiq8iLGRdJNV3DenL1pm4JoSVnj5m+0LZ4ha6spjdDI9n3xqjwbnW9w=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; BN3PR0101MB1026; 7:cy1tiNUfed3rAOYsJjXLD7l1XsR8P7ZO+y14s/JUmfAI2lAIcgts2LWtMXYJ6Ttpk6c6/cmF2dTJN2z6hA8D1h0Tl9Q2YYY2DVCLr6CQ9/jMih9mf9ZQoni4vxnWatYBC9lAQhetzb59VgposGdpCcssUW6+QCL9ndUHZwbcvEF5h7uGpCJ592H91zA0jpHAaSBBFPGtajFZxAtMtsMerCKy+gidafeblv6Go1hutmFiHkmLCkUoH2456tTe/m9mYgSXp3YRQP4T+qGT/4hzx9fCnz2q7no8n691vXimucvMgoL+FhTW9kXjqv5kRtD/r3KU6TCDS7ULYRfs750tvbH4rePxrWR57v++iJyw90FlqAoNwIujcjzWuLYpNRc2rCIJdt8HPygwiXex556MYZhknZIaKHBnL6mq3m4s2C9DsgldOU/KEXmZMsUSZ3MVMS5cENiyPpBhMUQuMZpkGSlna2/v3J+Xe9svss/eqhoHjv1bHbYCJoIY7Usot0dgpsSVS3QK5PaXQCxE/yoHobnsGrbn8LbuZSSLUjoeAhOqRrvPjZpiW3Aa2GKus83zoS6G6ZG+yQLUO94TDTsOzdFSA75dwxadihXIlabGDUjoJozd49PYjD/gpUVTJ8KPxpwyo8tmTi1AsbHEsSejg8XD2n19evXLXHdm+WggDBtJya8jijnfe+xNaAjiq3dKv29jRpObaZ6gQ9fWxDN6eMSsR7wy2bzfEwMZx2Y5Kg0HJX2N1hygDfcq4Tt8Dt4K89eyoIyL3VIlH+wbGA2vpwKDPU4fERw1BNKBKQJfptw=
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2017 17:06:32.0346 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR0101MB1026
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/lR0LRlFjfN9Q1e7SXVCKe9SrvQs>
Subject: Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 17:06:40 -0000

On 17 Jul 2017, at 19:01, Roland Dobbins wrote:

> Many organizations do this, today.

And some also go the passive-only route - I forgot to mention that.  
They'll use commercial IDS/IPS, or Snort with viewssld, et. al.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>