Announcing httpsy://, a YURL scheme

Tyler Close tyler at waterken.com
Mon Jul 14 20:33:16 EDT 2003


Please read the provided documentation.

On Monday 14 July 2003 18:45, Ed Gerck wrote:
> I did not see the issues of spoofing,

http://www.waterken.com/dev/YURL/Name/

> MITM

http://www.waterken.com/dev/YURL/Definition/#Site_authentication

> and revocation

http://www.waterken.com/dev/YURL/Why/#Certificate_lifecycle_control

> being addressed at all.

Then you simply did not read the documentaion.

> For these threats, however, the attack descriptions are
> well-known and rather easy to carry out.

Then do it. I asked you for the attack steps because you cannot
provide them.

No more hand-waving please. The provided documentation provides
technical detail and examples. I expect counter-arguments to do
the same.

Tyler

-- 
The union of REST and capability-based security:
http://www.waterken.com/dev/Web/

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list