Re: [Uta] Fwd: New Version Notification for draft-sheffer-uta-tls-attacks-00.txt

Watson Ladd <watsonbladd@gmail.com> Sat, 08 February 2014 22:10 UTC

Return-Path: <watsonbladd@gmail.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C71F1A060E for <uta@ietfa.amsl.com>; Sat, 8 Feb 2014 14:10:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7w2b9GRviA-V for <uta@ietfa.amsl.com>; Sat, 8 Feb 2014 14:10:53 -0800 (PST)
Received: from mail-yh0-x22f.google.com (mail-yh0-x22f.google.com [IPv6:2607:f8b0:4002:c01::22f]) by ietfa.amsl.com (Postfix) with ESMTP id E52811A0420 for <uta@ietf.org>; Sat, 8 Feb 2014 14:10:52 -0800 (PST)
Received: by mail-yh0-f47.google.com with SMTP id c41so3826478yho.6 for <uta@ietf.org>; Sat, 08 Feb 2014 14:10:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=VHAwBEUXHP+8AnH1zywh5WTBb9BQWDQV4qPm9hrgr04=; b=0D62nSS6TiG8IT2vA6XjbeXABk76vsFjRZ1vsD69J5rV0YioL0DMohdeCnRsjLhGM9 XkReTozqQFXs8iZ3xqrTYFOPJhrH+9J5epQ6TkFV09STZbzf/uheGbzFl5SKXYlTL4po TCLVx9CVBdmNZ2q2YiGaXHWcnleU45nZppkMF4THZkwq+EUyQRSXh+lZ5OA7vLn5wsbZ beKowBMo8LV1RvINh1POGuL+77xthb1FBesqpVCWCngMIbvAXu+4viEfxzrIbCeP/OQI gd/S5FDaMIkh/cgI4aUJINmPHkFYTVDh16xftY5iVpUtwWQ/ByLOH7zLEpbvS00lioYR 2pMQ==
MIME-Version: 1.0
X-Received: by 10.236.194.40 with SMTP id l28mr159347yhn.63.1391897453214; Sat, 08 Feb 2014 14:10:53 -0800 (PST)
Received: by 10.170.164.212 with HTTP; Sat, 8 Feb 2014 14:10:53 -0800 (PST)
In-Reply-To: <52F6A871.2040602@gmail.com>
References: <20140208055445.30181.46471.idtracker@ietfa.amsl.com> <52F6A871.2040602@gmail.com>
Date: Sat, 08 Feb 2014 14:10:53 -0800
Message-ID: <CACsn0cmCeU_-1a0kXTth7CsxF6DCJa9u1r_fK7V8gLUHDFYQkw@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
To: Yaron Sheffer <yaronf.ietf@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Cc: "uta@ietf.org" <uta@ietf.org>
Subject: Re: [Uta] Fwd: New Version Notification for draft-sheffer-uta-tls-attacks-00.txt
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 08 Feb 2014 22:10:55 -0000

On Sat, Feb 8, 2014 at 1:58 PM, Yaron Sheffer <yaronf.ietf@gmail.com> wrote:
> Hi,
>
> This contribution should cover the working group's first deliverable, per
> the chairs' list
> (http://www.ietf.org/mail-archive/web/uta/current/msg00053.html). The
> document is essentially Sec. 2 of draft-sheffer-tls-bcp, with barely any
> changes.
>
> Comments and especially additions about application-specific attacks are
> most welcome.

How about the issues relating to validating certificates, particularly
in non-browser code?

For reference https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html
is a good start.

Sincerely,
Watson Ladd
>
> Thanks,
>         Yaron
>
>
> -------- Original Message --------
> Subject: New Version Notification for draft-sheffer-uta-tls-attacks-00.txt
> Date: Fri, 07 Feb 2014 21:54:45 -0800
> From: internet-drafts@ietf.org
> To: Yaron Sheffer <yaronf.ietf@gmail.com>, "Ralph Holz"
> <holz@net.in.tum.de>, Peter Saint-Andre <ietf@stpeter.im>, Ralph Holz
> <holz@net.in.tum.de>, "Peter Saint-Andre" <ietf@stpeter.im>, "Yaron Sheffer"
> <yaronf.ietf@gmail.com>
>
>
> A new version of I-D, draft-sheffer-uta-tls-attacks-00.txt
> has been successfully submitted by Yaron Sheffer and posted to the
> IETF repository.
>
> Name:           draft-sheffer-uta-tls-attacks
> Revision:       00
> Title:          Summarizing Current Attacks on TLS and DTLS
> Document date:  2014-02-07
> Group:          Individual Submission
> Pages:          7
> URL:
> http://www.ietf.org/internet-drafts/draft-sheffer-uta-tls-attacks-00.txt
> Status: https://datatracker.ietf.org/doc/draft-sheffer-uta-tls-attacks/
> Htmlized:       http://tools.ietf.org/html/draft-sheffer-uta-tls-attacks-00
>
>
> Abstract:
>    Over the last few years there have been several serious attacks on
>    TLS, including attacks on its most commonly used ciphers and modes of
>    operation.  This document summarizes these attacks, with the goal of
>    motivating generic and protocol-specific recommendations on the usage
>    of TLS and DTLS.
>
>
>
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> The IETF Secretariat
>
>
>
> _______________________________________________
> Uta mailing list
> Uta@ietf.org
> https://www.ietf.org/mailman/listinfo/uta



-- 
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin