Re: Attacks on IPsec

From: Mike Amling (nospam_at_nospam.com)
Date: 05/18/05


Date: Wed, 18 May 2005 20:50:22 GMT

Gregory G Rose wrote:
> Oh, yes, if you use ESP, it automatically has
> integrity protection. But it's perfectly allowable
> to negotiate the NULL integrity algorithm.

   This is why security software should not be as configurable as the
average committee thinks it should be.
   For another example, the choice of encryption algorithm negotiated in
SSL can be None. Admittedly, that option is off by default in the only
browser I've checked (Netscape).

--Mike Amling



Relevant Pages

  • Re: Attacks on IPsec
    ... >>integrity protection. ... >>to negotiate the NULL integrity algorithm. ... There is always a danger in having cryptographic standards implemented by ... details of which implementations are affected by this recent report. ...
    (sci.crypt)
  • Re: Attacks on IPsec
    ... >integrity protection. ... >to negotiate the NULL integrity algorithm. ... I didn't realize that's allowed by the spec. ...
    (sci.crypt)
  • Re: IPsec - got ESP going, but not AH
    ... it's more straightforward to use ESP ... with integrity protection. ... (hmac-md5 is probably still fine, ... I believe that in tunnel mode AH and ESP integrity are essentially ...
    (FreeBSD-Security)
  • Re: More lies from the adulteress
    ... Get a language or shut your cocksucking mouth. ... Esp. ... about how well you think you suck cock. ... I do not "negotiate" for half my baby back, ...
    (rec.arts.poems)
  • hercules v undertaker
    ... does anyone have this match on tape ... i am willing to buy (we can negotiate) this from you esp if it has ... hercules clotheslining undertaker over the top rope ...
    (rec.sport.pro-wrestling)