[prev in list] [next in list] [prev in thread] [next in thread] 

List:       cryptography
Subject:    Yahoo + iPhone = replay attacks
From:       "Perry E. Metzger" <perry () piermont ! com>
Date:       2007-07-19 22:54:27
Message-ID: 87wswwxavw.fsf () snark ! piermont ! com
[Download RAW message or body]


A blog entry which claims that the proprietary "Push IMAP" protocol
that Apple and Yahoo came up with is deeply flawed -- the entry states
that the entire thing is vulnerable to trivial replay attacks.

http://blog.dave.cridland.net/?p=32

Hat tip: Marshall Rose

If true, this is yet more evidence for the ancient hypothesis that it
is foolish to roll your own security protocols.

Perry
-- 
Perry E. Metzger		perry@piermont.com

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic