Re: [cryptography] OTR and XMPP

2014-04-24 Thread Jim Fenton
On 04/07/2014 11:29 PM, ianG wrote: On 8/04/2014 03:13 am, Pranesh Prakash wrote: Dear all, In the March IETF 89 meeting in London, there were renewed discussions around end-to-end encryption in XMPP. Here is the recording of the session:

Re: [cryptography] DKIM: Who cares?

2012-10-26 Thread Jim Fenton
On 10/24/12 9:18 PM, Jon Callas wrote: Note the weasel-words long-lived. I think that the people caught out in this were risking things -- but let's also note that the length of exposure is the TTL of the DNS entries. I wouldn't characterize those as weasel-words, but rather that they were

Re: [cryptography] Secure Remote Password (SRP) and Plaintext Emil Address

2012-10-19 Thread Jim Fenton
On 10/18/12 11:45 PM, James A. Donald wrote: On 2012-10-19 11:47 AM, Nico Williams wrote: Lack of client ID privacy protection can lead to some attacks such as password guesses based on the ID or knowledge of the person that ID is for. If you were working for a spy agency (say), you'd

Re: [cryptography] can the German government read PGP and ssh traffic?

2012-06-06 Thread Jim Fenton
On 6/2/12 6:15 AM, Joe St Sauver wrote: ianG asked: #Would it be possible to describe in general words what LOA-1 thru 4 entails? I hesitate to try to do so. The definitive answer can be found in http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf The latest version,