Fwd: Tor security advisory: DH handshake flaw
Ben Laurie
ben at algroup.co.uk
Tue Aug 30 15:17:07 EDT 2005
Simon Josefsson wrote:
> No, the certificate is verifiable in deterministic polynomial time.
> The test is probabilistic, though, but as long as it works, I don't
> see why that matters. However, I suspect the ANSI X9.80 or ISO 18032
> paths are more promising. I was just tossing out URLs.
Surely Miller-Rabin is polynomial time anyway?
--
http://www.apache-ssl.org/ben.html http://www.thebunker.net/
"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list