anonymous DH & MITM
Ed Gerck
egerck at nma.com
Thu Oct 2 16:03:59 EDT 2003
bear wrote:
> You can have anonymous protocols that aren't open be immune to MITM
True.
> And you can have open protocols that aren't anonymous be immune to
> MITM.
True.
> But you can't have both.
False. In fact, it is possible to prove the existence of at least one open and
anonymous protocol that is immune to MITM in any given, feasible scenario
(ie, given a threat model).
Cheers,
Ed Gerck
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list