Re: [Uta] opportunistic keying / encryption considered of dubious value

Alyssa Rowan <akr@akr.io> Mon, 17 March 2014 14:37 UTC

Return-Path: <akr@akr.io>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5AE201A0400 for <uta@ietfa.amsl.com>; Mon, 17 Mar 2014 07:37:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wArI-bHI4z6f for <uta@ietfa.amsl.com>; Mon, 17 Mar 2014 07:37:31 -0700 (PDT)
Received: from entima.net (entima.net [78.129.143.175]) by ietfa.amsl.com (Postfix) with ESMTP id 780AE1A0125 for <uta@ietf.org>; Mon, 17 Mar 2014 07:37:31 -0700 (PDT)
Received: from [10.113.169.78] (94.197.120.48.threembb.co.uk [94.197.120.48]) by entima.net (Postfix) with ESMTPSA id EFD796011B for <uta@ietf.org>; Mon, 17 Mar 2014 14:37:22 +0000 (GMT)
User-Agent: K-9 Mail for Android
In-Reply-To: <2A0EFB9C05D0164E98F19BB0AF3708C711FCB076AD@USMBX1.msg.corp.akamai.com>
References: <53249D4E.2080104@network-heretics.com> <5324ECFC.2050004@akr.io> <2A0EFB9C05D0164E98F19BB0AF3708C711FCB076AD@USMBX1.msg.corp.akamai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="UTF-8"
From: Alyssa Rowan <akr@akr.io>
Date: Mon, 17 Mar 2014 14:37:17 +0000
To: "uta@ietf.org" <uta@ietf.org>
Message-ID: <3cab616b-d4f1-41c1-8488-25a2afaef9ff@email.android.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/uta/N1hQu5WUmSqBSBWh2Xrnzp48KXw
Subject: Re: [Uta] opportunistic keying / encryption considered of dubious value
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Mar 2014 14:37:35 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 17 March 2014 13:55:22 GMT+00:00, "Salz, Rich" <rsalz@akamai.com> wrote:
>You're not worried about imbuing a false sense of security?

User-agents MUST NOT indicate that an unauthenticated connection is secure.

There. Done. No locks, no https:.

>> Gosh, that was easy.
>Maybe not.
Seems easy enough to me. :-)

- --
/akr
-----BEGIN PGP SIGNATURE-----
Version: APG v1.0.9

iQI3BAEBCgAhBQJTJwidGhxBbHlzc2EgUm93YW4gPGFrckBha3IuaW8+AAoJEOyE
jtkWi2t6O6EQAL3NOlstdclWtKcMBXwzCk380ZI6HxoUvCuKwr104GA69LUGeTtz
JUu88LdtlZI2x88EuIoYSFHLoHH/KV5TqZ/Acit64mzT9LO17GYmQu37vKUZVqpR
sCztgMvt5xjB8cHyFPLtKFhzTMIC6kI3q+i6jK8rWo/dqifH+pwwx8igNcfPZFqg
oQZQbHFbBVaXaGmsZOC1cHfgI6eAiSdi3cj+T9OiMcmmKvpAiIaaURdi2EdRHLKQ
ZjYr0LEfskqLLR/r3x+dk4350aMQMyF+l6kYnwzbcsD7NqJDWVnZaNedIgpKkg6v
JMs6fz+I/WMdN1zHe99l5PChmO+MScA+jq/eife0jEWBfAfV23N8e87hisHDlVTL
hWi2LDY4P59gIdewBa+YAAuIBIaASQLhCm4UEJvxXJz0ZczLXMEijruVBUgRw6aY
W5YxzenOgD4ihPDi6i8OWwDVGmCdRFHVVySZemu0bGSpj0JjJnNfAT20qJ7w7ToS
Yw1ENca6IifceRooFfktETc0Kg8B9in8KbTIwdf5zfBBPXhHwkrASM7LJzxp0FBu
KRSN6ac9GiuYAvTPmy0ryMqXEzH8q0bJFoDpbrPqFgKQnlQX/jgpmWdg/zStK2X5
YS5/8SN7WPtD5FpVUmdDc3wuMOUxWcnO/7GRrZPvSO4/3nDyk/ehr8yv
=keLU
-----END PGP SIGNATURE-----