<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.mattsson-tls-psk-ke-dont-dont-dont" target="https://datatracker.ietf.org/doc/html/draft-mattsson-tls-psk-ke-dont-dont-dont-05">
   <front>
      <title>NULL Encryption and Key Exchange Without Forward Secrecy are Discouraged</title>
      <author initials="J. P." surname="Mattsson" fullname="John Preuß Mattsson">
         <organization>Ericsson AB</organization>
      </author>
      <date month="January" day="19" year="2023" />
      <abstract>
	 <t>   Massive pervasive monitoring attacks using key exfiltration and made
   possible by key exchange without forward secrecy have been reported.
   If key exchange without Diffie-Hellman is used, static exfiltration
   of the long-term authentication keys enables passive attackers to
   compromise all past and future connections.  Malicious actors can get
   access to long-term keys in different ways: physical attacks,
   hacking, social engineering attacks, espionage, or by simply
   demanding access to keying material with or without a court order.
   Exfiltration attacks are a major cybersecurity threat.  If NULL
   encryption is used an on-path attacker can read all application data.
   The use of psk_ke and NULL encryption are not following zero trust
   principles of minimizing the impact of breach and governments have
   already made deadlines for their deprecation.  This document
   evaluates TLS pre-shared key exchange modes, (EC)DHE groups,
   signature algorithms, and cipher suites and downgrades many entries
   to &quot;N&quot; and &quot;D&quot; where &quot;D&quot; indicates that the entries are
   &quot;Discouraged&quot;.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-mattsson-tls-psk-ke-dont-dont-dont-05" />
   
</reference>
