3 ms·
So then what stops a down grade attack? The attack would no longer leak encrypted data sure but now it acts as a dos attack. In reality the user would use anoth
by dangerface 4y ago
So then what stops a down grade attack? The attack would no longer leak encrypted data sure but now it acts as a dos attack. In reality the user would use another method one that is probably easier to break than the latest best crypto.
Without secure crypto we can't securely establish which primitives to use.
- mustache_kimono 4y agoI guess I'm wondering what you're getting at. Are you saying a more inflexible/less agile model is a better model? Doesn't that have a similar problem? When say, for example, Wireguard's choices become obsolete doesn't that operate like a DOS as well? What's your point?
- dangerface 4y ago> Are you saying a more inflexible/less agile model is a better model? No I am saying there is no secure answer. Both choices result in the same thing use one primitive when it becomes broken the protocol is broken, or negotiate a primitive and face downgrade attacks that make the protocol broken. There is no secure answer to stop mitm attack from the protocol level it has to come from cryptography at which point what happens when that cryptography is broken? The whole thing is a chicken and egg problem, there is no secure answer.
- orev 4y agoIt has to be taken as a given that all encryption deployed today will get “weaker” over time, so that’s already accounted for. The solution is that you just have to live with some risk from older algorithms, and make sure the replacement schedule is reasonably fast. You only need the absolute highest levels of security for a very few things, and if those are so critical then cutting off access is probably the right choice if the best algorithms aren’t available. Presumably those situations are in well-controlled environments and everyone is aware and can manage that type of coordination.