Gary E. Miller via devel <devel@ntpsec.org>:
> > Why are you fighting so hard for the reuse case?
> 
> Because the Proposed RFC allows for it, so some will use it.  We need to
> be interroperable.  It may be useful for bad connections.

While I concded your point that we need to plan for interoperability, Gary,
I'm going to put my foot down about not *defaulting* to re-use.

Why not?  Because my spider-sense tells me that if (and *only* if) we
rely on that, some clever bastard is going to come up with a bizarre,
previously-unimagined spin on a replay attack. Because that's just the
way the Dread God Finagle rolls.
-- 
                <a href="http://www.catb.org/~esr/";>Eric S. Raymond</a>

My work is funded by the Internet Civil Engineering Institute: https://icei.org
Please visit their site and donate: the civilization you save might be your own.


Attachment: signature.asc
Description: PGP signature

_______________________________________________
devel mailing list
devel@ntpsec.org
http://lists.ntpsec.org/mailman/listinfo/devel

Reply via email to