Dutch Transport Card Broken

Peter Gutmann pgut001 at cs.auckland.ac.nz
Thu Jan 31 19:15:09 EST 2008


Victor Duchovni <Victor.Duchovni at MorganStanley.com> writes:

>Jumping in late, but the idea that *TCP* (and not TLS protocol design) adds
>round-trips to SSL warrants some evidence (it is very temping to express this
>skepticism more bluntly).

If anyone's interested, I did an analysis of this sort of thing in an
unpublished draft "Performance Characteristics of Application-level Security
Protocols", http://www.cs.auckland.ac.nz/~pgut001/pubs/app_sec.pdf.  It
compares (among other things) the cost in RTT of several variations of SSL and
SSH.  It's not the TCP RTTs that hurt, it's all the handshaking that takes
place during the crypto connect.  SSH is particularly bad in this regard.

Peter.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list