Re: [TLS] Authentication weaker in PSK-mode?

2022-07-20 Thread Benjamin Kaduk
On Wed, Jul 20, 2022 at 01:34:12PM +0200, Ben Smyth wrote: > Authentication feels weaker in PSK-mode: > > * A server proves possession of a (short-term) shared key, > > whereas, with certificate-based authentication, > > * A server proves possession of a (long-term) private key; > > should we

[TLS] Authentication weaker in PSK-mode?

2022-07-20 Thread Ben Smyth
Authentication feels weaker in PSK-mode: * A server proves possession of a (short-term) shared key, whereas, with certificate-based authentication, * A server proves possession of a (long-term) private key; should we consider PSK-mode authentication weaker than certificate-based