OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] JaPCrypt

From: coderman (codermangmail.com)
Date: Wed Feb 06 2008 - 05:59:30 CST


On Feb 6, 2008 3:21 AM, Gerardo Di Giacomo <gerardolinux.it> wrote:
> ...
> The PSK is never sent, neither by the client neither by the server.

apologies, i will be more clear:

since psk without key distribution nor secure secret exchange does not
solve the problems that HTTPS solves, to say this is useful in
situations where HTTPS is not available is disingenuous.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/