Re: http+aes

On Mon, Mar 5, 2012 at 10:09 AM, Poul-Henning Kamp <>wrote:

> I'm sorry, but IMO this is just security-theater, and it represents
> so terrible handling of key-material that it is deeply irresponsible
> to even mention it in a standards document, without a lengthy list
> of caveats and disclaimers.

Could you elaborate on this? In particular, what risks do you believe exist
here given the scenario this is intended to address and given the list of
issues to consider already given in the specification?

I'm eager to address any problems that exist with this proposal, but I am
failing to reconcile the proposal as I understand it with your assessment
of it above.

Ian Hickson

Received on Monday, 5 March 2012 23:21:14 UTC