anonymous DH & MITM

Tim Dierks tim at dierks.org
Fri Oct 3 19:31:56 EDT 2003


I'm lost in a twisty page of MITM passages, all alike.

My point was that in an anonymous protocol, for Alice to communicate with 
Mallet is equivalent to communicating with Bob, since the protocol is 
anonymous: there is no distinction. All the concept of MITM is intended to 
convey is that in an anonymous protocol, you don't know who you're talking 
to, period. Mallet having two conversations with Alice & Bob is equivalent 
to Mallet intermediating himself into a conversation between Alice & Bob.

If you have some unintermediated channel to speak with a known someone 
once, you can exchange a value or values which will allow you to 
authenticate each other forevermore and detect any intermediations in the 
past. But the fundamental truth is that there's no way to bootstrap a 
secure communication between two authenticated parties if all direct & 
indirect communications between those parties may be intermediated. (Call 
this the 'brain in a jar' hypothesis.)

  - Tim

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list