Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SecDir review: mitigation against contextual attack #430

Closed
mcr opened this issue Aug 27, 2022 · 1 comment · Fixed by #438
Closed

SecDir review: mitigation against contextual attack #430

mcr opened this issue Aug 27, 2022 · 1 comment · Fixed by #438

Comments

@mcr
Copy link
Collaborator

mcr commented Aug 27, 2022

The review is at: https://mailarchive.ietf.org/arch/msg/last-call/0JpYvkgL-79nvmsrUpWKtMqtkhE
The review is positive, but asks for:

Even                       
if confidentiality is provided, the section goes on to state that information                        
can still be inferred by contextual or timing of the attestor exchange.  The                         
draft doesn’t describe ways to mitigate against this type of attack but should                       
give some guidance. 
@mcr
Copy link
Collaborator Author

mcr commented Sep 27, 2022

I'm not sure how, in an abstract architecture, we can mitigate against timing attacks. A specific protocol could propose mechanisms to defeat traffic analysis, but I don't think that the architecture can do this.
Other typos handled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant