Re: NSS implementation of TLS-PSK/ RFC 4279

2008-10-18 Thread Nelson B Bolyard
Ian G wrote, On 2008-10-14 14:27: > People in the apps security field hold out high hopes for TLS-PSK as > a great aid for phishing; it would be a shame of that didn't happen PSK is just a new name for a very old idea: shared secrets. When it comes to phishing, shared secrets aren't the solutio

Re: NSS implementation of TLS-PSK/ RFC 4279

2008-10-17 Thread Steffen Schulz
On 081014 at 23:45, Ian G wrote: > > No. There are no plans to include any PSK cipher suites in NSS. > > Because of the enormous potential for PSK cipher suites to be misused by > > application developers, there is strong resistance to incorporating them > > into NSS. > > Nelson, I'm fascinated b

Re: NSS implementation of TLS-PSK/ RFC 4279

2008-10-14 Thread Ian G
Nelson B Bolyard wrote: > [EMAIL PROTECTED] wrote, On 2008-10-14 13:52 PDT: >> I was wondering if implementation of TLS-PSK (RFC 4279) is currently in >> development. I do not see it in the current NSS source or roadmap. Thank >> you for any help. >> >> -John Engler > > No. There are no plans to

Re: NSS implementation of TLS-PSK/ RFC 4279

2008-10-14 Thread Nelson B Bolyard
[EMAIL PROTECTED] wrote, On 2008-10-14 13:52 PDT: > I was wondering if implementation of TLS-PSK (RFC 4279) is currently in > development. I do not see it in the current NSS source or roadmap. Thank > you for any help. > > -John Engler No. There are no plans to include any PSK cipher suites in N