From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on polar.synack.me X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,FREEMAIL_FROM autolearn=unavailable autolearn_force=no version=3.4.4 X-Received: by 10.129.154.16 with SMTP id r16mr2486614ywg.39.1458130176626; Wed, 16 Mar 2016 05:09:36 -0700 (PDT) X-Received: by 10.182.125.225 with SMTP id mt1mr43303obb.17.1458130176577; Wed, 16 Mar 2016 05:09:36 -0700 (PDT) Path: eternal-september.org!reader01.eternal-september.org!reader02.eternal-september.org!news.eternal-september.org!mx02.eternal-september.org!feeder.eternal-september.org!usenet.blueworldhosting.com!feeder01.blueworldhosting.com!peer02.iad.highwinds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!w104no7003334qge.1!news-out.google.com!k1ni186igd.0!nntp.google.com!nt3no2133438igb.0!postnews.google.com!glegroupsg2000goo.googlegroups.com!not-for-mail Newsgroups: comp.lang.ada Date: Wed, 16 Mar 2016 05:09:36 -0700 (PDT) In-Reply-To: <87wpp3ar1l.fsf@jester.gateway.pace.com> Complaints-To: groups-abuse@google.com Injection-Info: glegroupsg2000goo.googlegroups.com; posting-host=169.0.179.123; posting-account=p-xPhAkAAADjHQWEO7sFME2XBdF1P_2H NNTP-Posting-Host: 169.0.179.123 References: <5011d79c-aaad-464e-a68e-c31a2738a820@googlegroups.com> <87a8lzcv5a.fsf@jester.gateway.pace.com> <87wpp3ar1l.fsf@jester.gateway.pace.com> User-Agent: G2/1.0 MIME-Version: 1.0 Message-ID: Subject: Re: Ada for the TLS/SSL problem? From: Peter Brooks Injection-Date: Wed, 16 Mar 2016 12:09:36 +0000 Content-Type: text/plain; charset=ISO-8859-1 X-Received-Bytes: 2003 X-Received-Body-CRC: 3318761316 Xref: news.eternal-september.org comp.lang.ada:29801 Date: 2016-03-16T05:09:36-07:00 List-Id: On Wednesday, 16 March 2016 08:13:44 UTC+2, Paul Rubin wrote: > Peter Brooks writes: > > Excellent - maybe the time for the idea is here. > > I talked with some crypto people about it this evening and they were > supportive of the idea, though the general feeling these days is that > TLS sucks. > Yes, both SSL and TLS have problems. The only reason for saying 'TLS' is to give an idea of the project. My feeling is that we'd need a general, configurable, security layer. This can be proved to work by implementing TLS. However, stage 2 would be to develop a better, Ada-based, security layer. That would mean also having an Ada plug-in for browsers. Then it would be possible to have a secure security layer.