On Jul 25, 2024, at 12:26 PM, Michael Jones <[email protected]> wrote:
Thanks Lawrence, For what it’s worth, based on discussions in the JOSE WG meeting on Monday, the next draft will not include the ECDH algorithm registration -52 that you’re referring to (or any other ECDH registrations). I obviously fully support dealing with cross-mode attacks in COSE. But the Fully-Specified Algorithms draft looks like it’s not going a place to do this. Right. Fully-specified won’t fix cross-mode. But we could create only one new alg ID to identify both behavior changes rather than fanning out alg IDs. LL
_______________________________________________ COSE mailing list -- [email protected] To unsubscribe send an email to [email protected]
