I definitely want to avoid making prescriptive statements about what to protect, even couched as suggestions. However, I think that a more generic statement that describes the characteristics of a header that might need protection is definitely a good idea.
If Herve doesn't get there first, I can purpose text that concentrates on the coincidence of secret and small/easy-to-guess..
On Jan 22, 2015 3:17 PM, "Jari Arkko" <jari.arkko@xxxxxxxxx> wrote:
Thanks for the response. I think this may slightly enhance the feeling that the list may not be needed.
Jari