Re: [IPsec] DDoS puzzle: PRF vs Hash

2015-02-09 Thread Yaron Sheffer
Re: session resumption, I would like to propose the following text: 6.1. Session Resumption When the Responder is under attack, it MAY choose to prefer previously authenticated peers who present a session resumption [RFC 5723] ticket. The Responder MAY require such Initiators to include a

Re: [IPsec] DDoS puzzle: PRF vs Hash

2015-02-09 Thread Yoav Nir
On Feb 9, 2015, at 4:03 AM, Paul Wouters p...@nohats.ca wrote: On Sun, 8 Feb 2015, Yaron Sheffer wrote: I think we've come a full circle. We now have a proposal that makes proof-of-work more deterministic for each type of client (which I find very useful). But the weaker clients will