anonymous DH & MITM

Ed Gerck egerck at nma.com
Thu Oct 2 16:03:59 EDT 2003



bear wrote:

> You can have anonymous protocols that aren't open be immune to MITM

True.

> And you can have open protocols that aren't anonymous be immune to
> MITM.

True.

> But you can't have both.

False. In fact, it is possible  to prove the existence of at least one open and
anonymous protocol that is immune to MITM in any given, feasible scenario
(ie, given a threat model).

Cheers,
Ed Gerck

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list