4 ms·
> The reliance on OCB is unfortunate. I wish the Mosh developers would introduce multiple cipher schemes so that people can move away from OCB. Isn't OCB an op
by Flowdalic 9y ago
> The reliance on OCB is unfortunate. I wish the Mosh developers would introduce multiple cipher schemes so that people can move away from OCB.
Isn't OCB an open standard? https://www.rfc-editor.org/rfc/rfc7253.txt https://www.rfc-editor.org/rfc/rfc7253.txt
- tptacek 9y ago"Open standard" doesn't really mean anything. It's standardized, in that there is a standard (actually, multiple compatible standards) that you can code to and end up with interoperable OCB. The complaint upthread is that OCB is patented, which it is. But for many years now, OCB has been free for open source software.
- st3fan 9y agoThe license terms are vague. Is it connected to OpenSSL or not? Do you have to ask the author permission or not? And it is limited to open source software. Nobody wants to involve expensive lawyers, so for many folks that rules out OCB. Mosh is a great idea, but by connecting it to OCB, the authors completely stalled more widespread adoption. That, and like you said, the complete lack of protocol spec.
- tptacek 9y agoIt's not vague: it's not connected to OpenSSL. You do not need permission; you need to use an OSI-compliant license for your software.