sfs8 pt1

Dave Howe ukcrypto at chiark.greenend.org.uk
Mon, 29 Sep 2008 22:03:56 +0100


Charles Lindsey wrote:
> Sure, that makes sense. If you are the administrator of the server, then
> presumably you have access to the public keys anyway, so nothing wrong
> with using them to debug your IP traces.
> 
> But the article, as written, seemed to imply that the process could be
> performed from the client end. It needs to be more carefully written.

I am more concerned that, in the absence of DHE, a RIPa request for the
server key could decrypt historic data....