[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Proposed Extensions to TLS for OpenPGP



>> Some companies will undoubtedly never bring themselves to implementing one
>> of the above systems and will thus be relegated to snake oil security
>> internationally until the laws in the US change.
>I think it's unreasonable to say that 40 bit crypto is "snake oil".
>It's exactly as strong as advertised. There's no secret about the
>situation.

Yes, and quite useless.  Were one to map the security claims of 40-bit crypto to the drug industry, I would surprised if the product would merit anything more than a symptom reliever status.

>
>> Let's not infect our protocols with such politics.  TLS 1.0 is a done deal
>> as far as I'm concerned.  SSL3 had export algorithms, so TLS1 does too,
>> fine.  There are now many better solutions to the export problem,
>Perhaps, but you haven't suggested any.

Yes he has, your're just not accepting them.

--Steve