Dan,
I actually dug masquerade out of Williams Stallings' classic network
security book, but I like impersonate more.
spt
Dan Brown wrote:
Sean, Avshalom,
Maybe ”impersonate” is more specific than “masquerade”, as the latter
also connotes a party where the parties don masks.
Also, “impersonate” has some precedence in cryptographic terminology.
For example, American National Standard X9.63 for example lists an
attack called “Key Compromise Impersonation” which is when Eve being
able impersonate Alice to Bob, if Eve has stolen Bob’s private key.
Perhaps “misauthenticate” would be most specific, given that
“authenticate” is used all the time, but I don’t recall ever seeing
“misauthenticate”.
Best regards,
Dan
*From:* Avshalom Houri [mailto:[email protected]]
*Sent:* Thursday, January 14, 2010 9:41 AM
*To:* Sean Turner
*Cc:* Dan Brown; General Area Review Team; Tim Polk
*Subject:* Re: Gen Art LC review of: draft-turner-ecprivatekey-02.txt
Sean,
I am OK with the changes. I am not familiar with the right terms in this
field however, masquerades sound to me as only one of the possible
things that can be done by the person that gets the private key. They
can also have access to encrypted material for example. Anyway if you
think that masquerades is the right term in this field then I am OK with
it.
-Avshalom
From: Sean Turner <[email protected]>
To: Avshalom Houri/Haifa/i...@ibmil
Cc: General Area Review Team <[email protected]>,
[email protected], Tim Polk <[email protected]>
Date: 14/01/2010 04:33 PM
Subject: Re: Gen Art LC review of: draft-turner-ecprivatekey-02.txt
------------------------------------------------------------------------
Avashalom,
Thanks for the review. Responses below.
spt
Avshalom Houri wrote:
I have been selected as the General Area Review Team (Gen-ART)
reviewer for this draft (for background on Gen-ART, please see _
__http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html_).
Please resolve these comments along with any other Last Call comments
you may receive.
Document: draft-turner-ecprivatekey-02.txt
Reviewer: Avshalom Houri
Review Date: 2010-01-14
IETF LC End Date: 2010-01-14
IESG Telechat date: (if known)
Summary: The draft is ready for publication as an informational RFC. See
nits.
Major issues: None
Minor issues: None
Nits/editorial comments:
Lines 142-145
As specified in [RFC5480], only the namedCurve
CHOICE, which is an object identifier that fully identifies the
required values for a particular set of elliptic curve domain
parameters, is permitted.
Sentence is hard to read.
How about:
As specified in [RFC5480], only the namedCurve CHOICE is permitted.
namedCurve is an object identifier that fully identifies the required
values for a particular set of elliptic curve domain parameters.
Lines 145-146
Though the ASN.1 indicates parameters is OPTIONAL,
-> Though the ASN.1 indicates that the parameter parameters is OPTIONAL,
How about:
Though the ASN.1 indicates that the parameters field is OPTIONAL,
Line 196
masquerades
-> Not sure that this is the right term. Probably identity-theft or
similar should be used.
Masquerade is a generic term that covers one entity pretending to be
another entity. Identity-theft to me is a little too specific to
signature keys that I think might not entirely fit this because EC keys
aren't just used for identity. Disclosure of the private key is pretty
catastrophic so maybe I should just list more things that could happen:
Disclosure of the private-key material to another entity can lead to
active and passive attacks including: masquerade, unauthorized
disclosure, and unauthorized modification.
---------------------------------------------------------------------
This transmission (including any attachments) may contain confidential
information, privileged material (including material protected by the
solicitor-client or other applicable privileges), or constitute
non-public information. Any use of this information by anyone other than
the intended recipient is prohibited. If you have received this
transmission in error, please immediately reply to the sender and delete
this information from your system. Use, dissemination, distribution, or
reproduction of this transmission by unintended recipients is not
authorized and may be unlawful.
_______________________________________________
Gen-art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/gen-art