V6 - Proper/safe MAC usage (in contrast to digital signatures) #2310
Labels
2) Awaiting response
Awaiting a response from the original poster
AppendixV
Appendix with crypto details
V6
_5.0 - prep
This needs to be addressed to prepare 5.0
Should there be a requirement about the proper usage of MAC (in contrast to digital signatures). In particular, if there are more than two participants, MAC is usually not safe.
See for example Differences between Digital Signatures and MACs in the JWS RFC (emphasis mine):
Note: another problematic scenario mentioned here is when a MAC-ed message send from A to B could be sent again from B to A.
The text was updated successfully, but these errors were encountered: