On Fri, May 19, 2017 at 1:58 PM, Viktor Dukhovni <[email protected]> wrote: > > +1. The additive obfuscation leaks nothing that is not already leaked > just by sending the tickets. >
You're both right, that does work out. I was thinking my balanced equations stupidly and solving for x while forgetting that t1' is secret. -- Colm
_______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
