monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Re: netsync transport encryption?


From: Ulf Ochsenfahrt
Subject: Re: [Monotone-devel] Re: netsync transport encryption?
Date: Wed, 25 Oct 2006 21:43:13 +0200
User-agent: Icedove 1.5.0.7 (X11/20061013)

Zack Weinberg wrote:
In the scenario where the server is authenticated but the client isn't
(initial anonymous pull with the server's public key distributed some
other way, for instance), the man in the middle cannot impersonate the
server, and cannot gain any information that he could not have gotten
by just doing an anonymous pull himself.

In the scenario where neither side is authenticated (so we've fallen
back to D-H exchange) a man in the middle attack succeeds -- but this
is no worse than an unencrypted connection.  If what you're worried
about is eavesdropping rather than spoofing, you've still gained
security.

If you allow anonymous pull, encrypting the connection gives no security whatsoever. Correct me if I'm wrong.

Cheers,

-- Ulf

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]