Re: FYI: TLS Triple Handshake Attack

On 4 March 2014 00:21, Kingsley Idehen <> wrote:

> On 3/3/14 5:08 PM, Melvin Carvalho wrote:
> Yes, note "In short, the TLS handshake hashes in too little information,
> and always has. Because of that it's possible to synchronise the state of
> two TLS sessions in a way that breaks assumptions made in the rest of the
> protocol."
> Well, those assumptions will always be brittle if a TLS handshake is the
> be all and end all. Once again, this is why WebID, WebID+TLS, and Trust
> Logic are a much better solution for this problem.
> Our challenge remains:
> 1. getting the WebID spec out


I'd be keen to see the current version of the spec published.  To my
knowledge it's not been updated for about a year.  Over at the web payments
group they are working on a similar identity spec based on JSON LD (as
opposed to our Turtle version) and publishing out updates each week.  IMHO,
this is helping gain traction.

> 2. showcasing how it addresses these problems via RDF based Linked Data
> augmentation
> 3. cognitive dissonance that swirls around anything to do with RDF and the
> Semantic Web vision.
> --
> Regards,
> Kingsley Idehen
> Founder & CEO
> OpenLink Software
> Company Web:
> Personal Weblog:
> Twitter Profile:
> Google+ Profile:
> LinkedIn Profile:

Received on Tuesday, 4 March 2014 17:59:23 UTC