V6 - Proper/safe MAC usage (in contrast to digital signatures) #2310
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
V6
_5.0 - prep
This needs to be addressed to prepare 5.0
Should there be a requirement about the proper usage of MAC (in contrast to digital signatures). In particular, if there are more than two participants, MAC is usually not safe.
See for example Differences between Digital Signatures and MACs in the JWS RFC (emphasis mine):
Note: another problematic scenario mentioned here is when a MAC-ed message send from A to B could be sent again from B to A.
The text was updated successfully, but these errors were encountered: