Re: New Version Notification for draft-snell-httpbis-keynego-01.txt

I'm not talking about protecting those images-- I'm saying that without
integrity *always*, a MITM can always downgrade anything, and you can't
tell it was done.

> >Being able to run a handshake in parallel with whatever else can only
> >happen when one doesn't need or want the integrity handshake, which is
> >necessary for detecting a malicious filtering MITM (and yes one can never
> >*prevent* such, but detection is quite important).
> My impression of the average site needing protection is that they
> send me 100k of graphics to wrap around the two protected entry
> fields for "username" and "password".
> I dont get the impression that they're particularly worried about
> the integrity of the stock-photo of some smiling model or for
> that matter the company logo or...
