Sean Smith
Sat, 14 Aug 2004 13:10:11 -0700
has a TLS server (or client, for that matter) key ever actually been compromised?
Hi, Marc!
I don't know about in-the-wild attacks.
However, proof-of-concept attacks:
J. Marchesini, S.W. Smith, M.Zhao. "Keyjacking: The Surprising Insecurity of Client-side SSL" Computers and Security. To appear, 2004. http://www.cs.dartmouth.edu/~sws/abstracts/msz04.shtml
--Sean
--------------------------------------------------------------------- The Cryptography Mailing List Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]