On Jul 25, 2024, at 12:26 PM, Michael Jones <[email protected]> wrote:

Thanks Lawrence,

For what it’s worth, based on discussions in the JOSE WG meeting on Monday, the 
next draft will not include the ECDH algorithm registration -52 that you’re 
referring to (or any other ECDH registrations).

I obviously fully support dealing with cross-mode attacks in COSE.  But the 
Fully-Specified Algorithms draft looks like it’s not going a place to do this.

Right. Fully-specified won’t fix cross-mode. But we could create only one new 
alg ID to identify both behavior changes rather than fanning out alg IDs.

LL

_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to