Dan,

I actually dug masquerade out of Williams Stallings' classic network security book, but I like impersonate more.

spt

Dan Brown wrote:
Sean, Avshalom,

Maybe ”impersonate” is more specific than “masquerade”, as the latter also connotes a party where the parties don masks.

Also, “impersonate” has some precedence in cryptographic terminology. For example, American National Standard X9.63 for example lists an attack called “Key Compromise Impersonation” which is when Eve being able impersonate Alice to Bob, if Eve has stolen Bob’s private key.

Perhaps “misauthenticate” would be most specific, given that “authenticate” is used all the time, but I don’t recall ever seeing “misauthenticate”.

Best regards,

Dan

*From:* Avshalom Houri [mailto:[email protected]]
*Sent:* Thursday, January 14, 2010 9:41 AM
*To:* Sean Turner
*Cc:* Dan Brown; General Area Review Team; Tim Polk
*Subject:* Re: Gen Art LC review of: draft-turner-ecprivatekey-02.txt

Sean,

I am OK with the changes. I am not familiar with the right terms in this field however, masquerades sound to me as only one of the possible things that can be done by the person that gets the private key. They can also have access to encrypted material for example. Anyway if you think that masquerades is the right term in this field then I am OK with it.

-Avshalom




From:        Sean Turner <[email protected]>
To:        Avshalom Houri/Haifa/i...@ibmil
Cc: General Area Review Team <[email protected]>, [email protected], Tim Polk <[email protected]>
Date:        14/01/2010 04:33 PM
Subject:        Re: Gen Art LC review of: draft-turner-ecprivatekey-02.txt

------------------------------------------------------------------------




Avashalom,

Thanks for the review. Responses below.

spt

Avshalom Houri wrote:
 I have been selected as the General Area Review Team (Gen-ART)
 reviewer for this draft (for background on Gen-ART, please see _
 __http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html_).

 Please resolve these comments along with any other Last Call comments
 you may receive.

 Document: draft-turner-ecprivatekey-02.txt
 Reviewer: Avshalom Houri
 Review Date: 2010-01-14
 IETF LC End Date: 2010-01-14
 IESG Telechat date: (if known)

 Summary: The draft is ready for publication as an informational RFC. See
 nits.

 Major issues: None

 Minor issues:  None

 Nits/editorial comments:

 Lines 142-145
      As specified in [RFC5480], only the namedCurve
      CHOICE, which is an object identifier that fully identifies the
      required values for a particular set of elliptic curve domain
      parameters, is permitted.

 Sentence is hard to read.

How about:

As specified in [RFC5480], only the namedCurve CHOICE is permitted.
namedCurve is an object identifier that fully identifies the required
values for a particular set of elliptic curve domain parameters.

 Lines 145-146
 Though the ASN.1 indicates parameters is OPTIONAL,
 -> Though the ASN.1 indicates that the parameter parameters is OPTIONAL,

How about:

Though the ASN.1 indicates that the parameters field is OPTIONAL,

 Line 196
 masquerades

 -> Not sure that this is the right term. Probably identity-theft or
 similar should be used.

Masquerade is a generic term that covers one entity pretending to be
another entity.  Identity-theft to me is a little too specific to
signature keys that I think might not entirely fit this because EC keys
aren't just used for identity.  Disclosure of the private key is pretty
catastrophic so maybe I should just list more things that could happen:

Disclosure of the private-key material to another entity can lead to
active and passive attacks including: masquerade, unauthorized
disclosure, and unauthorized modification.

---------------------------------------------------------------------
This transmission (including any attachments) may contain confidential information, privileged material (including material protected by the solicitor-client or other applicable privileges), or constitute non-public information. Any use of this information by anyone other than the intended recipient is prohibited. If you have received this transmission in error, please immediately reply to the sender and delete this information from your system. Use, dissemination, distribution, or reproduction of this transmission by unintended recipients is not authorized and may be unlawful.
_______________________________________________
Gen-art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/gen-art

Reply via email to