[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [lemonade] Security Considerations Pawn Ticket URLs



Eric Burger writes:
Sigh.
Part of me says, "Get it done."
Another part of me says, "Internet protocol; cannot assume all in same administrative domain."
Reality is, "Informational document."
Thus, "Get it done" side of my brain wins. Go for stream+.

(Just my vote - if anyone feels strongly otherwise, please speak up
now!)

I didn't quite understand what the proposal is.

If I understand it: The proposal is to add a new knob to IMAP URIs which an entity (which? an IMAP server or client?) can add (where?). Access to the URI is then granted only to entities that are known to be streaming servers.

I don't see how this helps security. If I'm an attacker and have such a URI, then (AFAICT) I can obtain the data by connecting to the streaming

Arnt
_______________________________________________
lemonade mailing list
lemonade at ietf.org
https://www.ietf.org/mailman/listinfo/lemonade
Supplemental Web Site:
http://www.standardstrack.com/ietf/lemonade