[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Black Eye for NSA, NIST, and Denning




"Perry E. Metzger" says:
> However, it can be done in advance, and you can conceivably reuse
> forged LEAFs.

I will point out something that I didn't quite understand myself but
have since discussed with Matt Blaze in some detail -- LEAF checksums
are tied to session keys. You CAN do this in advance but only if your
key exchange will permit you to generate your session keys in advance,
too. Obviously, reusing forged LEAFs requrire requires reusing sesison
keys.

Perry