Re: [exim-dev] [Bug 1837] small subgroup attack

Top Page
Delete this message
Reply to this message
Author: Viktor Dukhovni
Date:  
To: exim-dev
Subject: Re: [exim-dev] [Bug 1837] small subgroup attack
On Sun, May 29, 2016 at 06:51:52AM +0000, Phil Pennock wrote:

> On 2016-05-29 at 02:10 -0400, Viktor Dukhovni wrote:
>
> > But, (broken record), do yourself a favour and just drop these groups...
>
> We can change the default. We can add new groups.
>
> We won't remove documented values, exposed to configuration, short of a
> release where we are accepting non-backwards-compatible changes.


OK, changing the default makes sense. You can also update the docs
to discourage use of the rfc5114 groups.

-- 
    Viktor.