On 30 October 2016 at 08:37, XMPP Extensions Editor <[email protected]> wrote:
> This message constitutes notice of a Last Call for comments on XEP-0300 (Use 
> of Cryptographic Hash Functions in XMPP).
>
> Abstract: This document provides recommendations for the use of cryptographic 
> hash functions in XMPP protocol extensions.
>
> URL: http://xmpp.org/extensions/xep-0300.html
>
> This Last Call begins today and shall end at the close of business on 
> 2016-11-12.
>
> Please consider the following questions during this Last Call and send your 
> feedback to the [email protected] discussion list:
>
> 1. Is this specification needed to fill gaps in the XMPP protocol stack or to 
> clarify an existing protocol?
> 2. Does the specification solve the problem stated in the introduction and 
> requirements?
> 3. Do you plan to implement this specification in your code? If not, why not?
> 4. Do you have any security concerns related to this specification?
> 5. Is the specification accurate and clearly written?
>
> Your feedback is appreciated!
> _______________________________________________
> Standards mailing list
> Info: https://mail.jabber.org/mailman/listinfo/standards
> Unsubscribe: [email protected]
> _______________________________________________


4.3:
> The currently known best attack against the pre-image resistance property of 
> the MD5 algorithm is slightly better than the generic attack and was released 
> 2009 [6].

I don't like the phrasing "currently"; better to say "As of 2016".

4.5:
> In fall 2015

Using seasons makes for much ambiguity. Please just use a date instead.

5.
> The current plan is to move SHA-1 to a SHOULD NOT, SHA-256, SHA3-256 and 
> BLAKE2b256 to MUST, and SHA-512, SHA3-512, and BLAKE2b512 to SHOULD by the 
> end of 2016.

Isn't it very close to the end of 2016 already? Why hasn't this happended.
See also "current"
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to