Correction

Eric Rescorla ekr at eit.COM
Tue Dec 13 08:39:44 PST 1994


My previous message about HTTP Security implied that you would
(in SHTTP) reuse the DEK from say an HTTP request for the reply.
You most certainly would not do this. (It's horribly bad
key hygiene.) Rather, SHTTP provides a way to exchange
a symmetric encryption key (in an HTTP message) that can subsequently
be used cover subsequent DEKs.

Sorry for the possible confusion...
-Ekr







More information about the cypherpunks-legacy mailing list