Re: TLS break

2009-11-10 Thread Tom Weinstein
orla has a protocol extension that appears to do the job. -- Give a man a fire and he's warm for a day, but set | Tom Weinstein him on fire and he's warm for the rest of his life.| twei...@pacbell.net - The Cryptography Mail

DTLS for Java?

2006-03-08 Thread Tom Weinstein
Does anyone know of a DTLS implementation for Java? I'd rather avoid using OpenSSL through JNI if I possibly can. -- Give a man a fire and he's warm for a day, but set | Tom Weinstein him on fire and he's warm for the rest of his life.| [

Re: "SSL stops credit card sniffing" is a correlation/causality myth

2005-06-02 Thread Tom Weinstein
f SSL is a necessary first step? You seem to be putting the cart in front of the horse. -- Give a man a fire and he's warm for a day, but set | Tom Weinstein him on fire and he's warm for the rest of his life.| [EMAIL PROTECTED]

Re: SSL, client certs, and MITM (was WYTM?)

2003-10-22 Thread Tom Weinstein
Ian Grigg wrote: Tom Weinstein wrote: In threat analysis, you have to base your assessment on capabilities, not intentions. If an attack is possible, then you must guard against it. It doesn't matter if you think potential attackers don't intend to attack you that way, because you re

Re: SSL, client certs, and MITM (was WYTM?)

2003-10-22 Thread Tom Weinstein
, then you must guard against it. It doesn't matter if you think potential attackers don't intend to attack you that way, because you really don't know if that's true or not and they can always change their minds without telling you. -- Give a man a fire and he's warm f

Re: WYTM?

2003-10-15 Thread Tom Weinstein
ser-friendly UI for crypto stuff that doesn't compromise security has been (and continues to be) the greatest obstacle to getting people to use this stuff. -- Give a man a fire and he's warm for a day, but set | Tom Weinstein him on fire and