per-entity - Re: [Per-Entity] HTTPS transport and TLS trust
Subject: Per-Entity Metadata Working Group
List archive
- From: Nicholas Roy <>
- To: <>
- Subject: Re: [Per-Entity] HTTPS transport and TLS trust
- Date: Fri, 23 Sep 2016 10:01:53 -0600
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:W0v5Jh10CopBytaRsmDT+DRfVm0co7zxezQtwd8ZsesQL/ad9pjvdHbS+e9qxAeQG96Eu7QZ0KGP7ujJYi8p39WoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6i760TlHTg3yL094IPj0Bp/6jsK80OW3/JuVZB9H0mmTe7R3eTO3pgXWssANybFlO+5lzAHOs1NJffhb32VlOQjVkhrhsJTjtKV/+jhd7qpyv/VLVr/3Kvw1
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
On 9/6/16 2:52 PM, Cantor, Scott wrote:
Just for the background information, another concern was the serverRight, that's the fundamental difference.
security which is assumed in TLS. I'm not suggesting md.incommon.org is
not secure but it was difficult to quantify and it was certainly less
secure than the signing operation. Ops also wanted to reserve the
flexibility of hosting its stand-by servers in co-locations without
special requirements on its physical security.
Signing Pro:
- self-contained / portable security model
Con:
- subject to MITM threats
Transport Pro:
- end to end security
Con:
- highly dependent on physical deployment characteristics that are difficult
to replicate widely
I wouldn't necessarily argue that both don't have their place, but we
implement both and long experience has led us to believe that it's better to
attack the MITM problem with signing somehow than give up the flexibility.
I think probably the best option is to sign, use TLS, but not go overboard
trying to lock down the TLS part. That provides reasonable protection against
low-cost active attacks without relying on it exclusively.
Strong +1 from me.
Nick
-- Scott
- RE: [Per-Entity] HTTPS transport and TLS trust, (continued)
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Tom Scavo, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Patrick Radtke, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Scott Koranda, 09/06/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/07/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Nicholas Roy, 09/23/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Scott Koranda, 09/06/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/07/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Cantor, Scott, 09/23/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Nicholas Roy, 09/23/2016
Archive powered by MHonArc 2.6.19.