On Wed, 29 Jun 2005, Sam Hartman wrote:
Please add an applicability statement discussing the performance advantages of RC4 against the known security weaknesses. You may end up reusing text from your security considerations text. Your applicability statement needs to suggest to the reader that they consider the ssh newmodes draft as an alternative to your rc4 ciphers. This alternative should be chosen in environments where the advantages of RC4 do not make it attractive.
I've done this and sent draft-harris-ssh-arcfour-fixes-03.txt to be posted.
In addition, I'm still waiting to hear back from you on the questions raised in the security directorate review. While these points are minor, they should be addressed.
I've replied to them, removed my dodgy information theory and referenced the relevant recent papers.
-- Ben Harris _______________________________________________ Ietf@xxxxxxxx https://www1.ietf.org/mailman/listinfo/ietf