Hey I don't know what it's called, but I'm wondering how one binds a challenge/response (or whatever you authenticate with) inside a secure tunnel to prevent the peer from relaying it on to another party to answer.
I assume it could be as simple as signing a nonce and some parameter of the channel (such as an ephemeral key) and sending that (or something derived from it) as the challenge, but curious what the options and tradeoffs are. -- Good code works on most inputs; correct code works on all inputs. My emails do not have attachments; it's a digital signature that your mail program doesn't understand. | http://www.subspacefield.org/~travis/ If you are a spammer, please email [email protected] to get blacklisted.
pgp1sVMqnkdnO.pgp
Description: PGP signature
_______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
