Re: Mandatory encryption *is* theater

From: Poul-Henning Kamp <phk@phk.freebsd.dk>
Date: Tue, 27 Aug 2013 11:32:15 +0000
cc: "ietf-http-wg@w3.org Group" <ietf-http-wg@w3.org>, Eliot Lear <lear@cisco.com>
Message-ID: <30273.1377603135@critter.freebsd.dk>
In message <CAA4WUYhPmTLHQa6DdGrVqxUjTwATBdSeqL-feATubfv66brZxw@mail.gmail.com>, =?UTF-8?B?V2lsbGlhbSBDaGFuIC
jpmYjmmbrmmIwp?= writes:

>Sorry, let me clarify with an example: a TLS connection to a server
>presenting a self-signed cert. It's encrypted, but the server is not
>authenticated. Does that clarify matters?

Yes, thanks.

I tend to prefer the words "privacy" and "secrecy" myself, exactly
because "encryption" is such a catch-all concept that you never quite
know what people actually mean.

Received on Tuesday, 27 August 2013 11:32:38 UTC

