[NNTP] Re: Comments on draft-ietf-nntp-tls-nntp-05.txt

Forrest J. Cavalier III forrest at mibsoftware.com
Thu May 26 14:16:19 PDT 2005


EKR wrote:

> Yes, I'm familiar with all this, but what's relevant here is not
> the absolute cost but the relative cost compared to other things that
> are taking up CPU (Amdahl's law again). That's why you need
> actual measurements.

Are you saying that to be sure the bridge falls down, you must
build the bridge first?

I am not a SASL expert, but think of the issue in general...

It is my understanding that using symmetric ciphers on known and
public plaintext (e.g. Usenet messages) allows easy recovery of
the encryption keys.

There is no way that asymmetric ciphers are fast enough even on
CLIENTS, let alone servers, to use them for a general purpose
Usenet session.

One-time pads can help, but they are expensive CPU and storage
wise too.

Is anything left?







More information about the ietf-nntp mailing list