[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Gopher TLS support in curl




On Mon, Dec 21 2020, Cameron Kaiser wrote:

That is a FANTASTIC trick!  Actually it could be expanded to
simply do plaintext for a non-TLS-capable client.  I personally
would prefer that, if only because I still want to use UMN gopher client sometimes. There is something about its lovely 90s feel...

I still don't understand how this can be protected against downgrade attacks. A malicious MITM could simply ensure that the TLS trigger byte was never communicated (race the packet, etc.) and both client and server
would then assume the connection isn't TLS.

Not a high risk, but if the end goal is security ...

True, true... And we don't really have a way to do HSTS, not that we'd want to. But then how could one ever migrate otherwise? I mean, you couldn't just move floodgap.com to TLS without breaking a bunch of links out there, right?

One starts to wonder if Tor onion services might make an easier target here...

John


Reply to: