ietf-nntp Draft 20 pre-release 2

Clive D.W. Feather clive at demon.net
Mon Oct 13 00:41:35 PDT 2003


Charles Lindsey said:
> Indeed so. If the security considerations are going to point out dangers
> of cacheing, then they should point out dangers of not consulting LIST
> EXTENSIONS as the same time.

Surely that only applies if LIST EXTENSIONS is carrying security
information? If the only thing the client knows about is XENCRYPT, then
there's no *security* issue in trying the command without LIST EXTENSIONS
first.

-- 
Clive D.W. Feather  | Work:  <clive at demon.net>   | Tel:    +44 20 8495 6138
Internet Expert     | Home:  <clive at davros.org>  | *** NOTE CHANGE ***
Demon Internet      | WWW: http://www.davros.org | Fax:    +44 870 051 9937
Thus plc            |                            | Mobile: +44 7973 377646



More information about the ietf-nntp mailing list