Sure, we can absolutely say “an independent machine-checked symbolic 
analysis…”, that’s no issue.

My point is that my analysis’s soundness is unusually easy to independently 
review. You can literally diff my extended ProVerif models against the ones 
from the previous publication:

https://github.com/symbolicsoft/reftls/tree/master/pv

… and see for yourself if they match the RFCs and the paper’s claims. Then you 
can run the models locally and check the analysis results for yourself. Note 
that this may take a few hours and consumes about 40GB of RAM in the worst 
case, however, so be careful in case your computer isn’t strong enough.

Agreeing on *how* to cite the analysis and asking questions about how to 
validate it strike me as much more productive ways forward than poopooing it 
based on the authors and the venue.

Nadim Kobeissi
Symbolic Software • https://symbolic.software

> On 8 Jun 2026, at 5:34 PM, Nathanael Ritz <[email protected]> wrote:
> 
> Comments inline with [NR]
> 
> On Mon, 8 Jun 2026 at 08:40, Salz, Rich <[email protected] 
> <mailto:[email protected]>> wrote:
> >> On 6/8/26, 12:28 AM, "Nathanael Ritz" <[email protected] 
> >> <mailto:[email protected]>> wrote:
> >> Independent machine-checked symbolic analysis using ProVerif [REF]
> >>
> > This gives too much credit to one individual’s work that is not in a 
> > peer-reviewed journal or conference.
> >
> 
> [NR] I think this argument -- or at very least the way it is stated -- is 
> unfortunate. 
>  
> > [...] maybe the first word should be “An …"
> > 
> 
> [NR] I disagree that the current phrasing gives "too much credit", but I 
> don't think adding an "an" would be unfair. Presuming you are suggesting 
> something like: "An independent machine-checked symbolic analysis using 
> ProVerif [REF]..."
> 
> -N
> 
> On Mon, 8 Jun 2026 at 08:40, Salz, Rich <[email protected] 
> <mailto:[email protected]>> wrote:
>> 
>> 
>> On 6/8/26, 12:28 AM, "Nathanael Ritz" <[email protected] 
>> <mailto:[email protected]>> wrote:
>> 
>> > Independent machine-checked symbolic analysis using ProVerif [REF]
>> 
>> This gives too much credit to one individual’s work that is not in a 
>> peer-reviewed journal or conference. Nothing against Nadim, he deserves all 
>> the credit for what he did, but let’s not overstate it. For example, maybe 
>> the first word should be “An …"
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to