[freenet-dev] Short refs was Re: alternative to #freenet-refs

Michael Rogers m.rogers at cs.ucl.ac.uk
Sun Nov 18 12:10:48 UTC 2007


Matthew Toseland wrote:
> We're assuming different attack models here. Both are valid for certain 
> assumptions.

Fair point - I accept that if you assume the exchange is unobservable, a
one-way invite can provide mutual authentication. But IMHO we shouldn't
make that assumption - eavesdropping is known to be widespread, whereas
at least we're still in the dark about the extent of active MITM. ;-)

Cheers,
Michael



More information about the Devl mailing list