The TLS hammer and resource integrity

Date: Thu, 29 Mar 2012 09:13:45 +0200
On 29 Mar 2012, at 08:46, Poul-Henning Kamp wrote:

> In message <4F7389AA.6050005@mozilla.com>, patrick mcmanus writes:
>> On 3/28/2012 11:42 PM, Willy Tarreau wrote:
>> You might care that someone else knows that you are seeing it (and are 
>> therefore present and watching your tv).
> You seem to forget that it takes two to tango:  There is a client and
> a server.  The server might not be wanting, able or even legally allowed
> to use crypto.

You mean the server may not be allowed to use crypto for encryption. I seriously
doubt a server may not be allowed to use crypto for integrity and identity. TLS
allows crypto to be used for integrity and identity without confidentiality. 
User interfaces do need to be improved to make this visible, but it is available.

