[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Authentication and email

Paul Hoffman / IMC <phoffman@imc.org> writes:

> >Any user agent that can send instant messages using SIP, MUST implement
> >S/MIME... if we believe that it is acceptable to send emails to the IETF
> >mailing lists without using any kind of security, why do we mandate
> >S/MIME for instant messages? That was the issue Dean was talking about.
> >3GPP was strongly opposed to that MUST S/MIME, but we insisted that it
> >had to be in the spec.
> Ah, now *there's* a topic worthy of IETF-wide discussion! Where was
> the security needed? What are the attack scenarios? Could it have
> been implemented optionally, like we have in mail?

Yea, and look how secure our email system is....  The IESG has already
stated that optional security is bad (because optional security means
no security).  Let's not revisit that rathole.

> --Paul Hoffman, Director
> --Internet Mail Consortium

-derek, co-chair IMPP
       Derek Atkins
       Computer and Internet Security Consultant
       derek@ihtfp.com             www.ihtfp.com