Lucrative List

2003-02-25 Thread R. A. Hettinga
--- begin forwarded text Status: RO From: Patrick [EMAIL PROTECTED] To: 'Digital Bearer Settlement List' [EMAIL PROTECTED] Subject: Lucrative List Date: Tue, 25 Feb 2003 11:04:21 -0600 Sender: [EMAIL PROTECTED] The Lucrative project now has a discussion mailing list. The scope of the list is:

Re: [Bodo Moeller bodo@openssl.org] OpenSSL Security Advisory: Timing-based attacks on SSL/TLS with CBC encryption

2003-02-25 Thread Anton Stiglic
Bodo Moeller wrote: Actually there are three choices: Pad-then-encrypt-then-MAC Pad-then-MAC-then-encrypt MAC-then-pad-then-encrypt It's true that pad-then-encrypt-then-MAC appears to be the safest approach in general, but pad-then-MAC-then-encrypt would also have

Re: [Bodo Moeller bodo@openssl.org] OpenSSL Security Advisory: Timing-based attacks on SSL/TLS with CBC encryption

2003-02-25 Thread Bodo Moeller
On Tue, Feb 25, 2003 at 10:41:51AM -0500, Anton Stiglic wrote: Bodo Moeller wrote: Actually there are three choices: Pad-then-encrypt-then-MAC Pad-then-MAC-then-encrypt MAC-then-pad-then-encrypt It's true that pad-then-encrypt-then-MAC appears to be the safest approach