%% You should probably cite draft-mattsson-tls-psk-ke-dont-dont-dont-05 instead of this revision. @techreport{mattsson-tls-psk-ke-dont-dont-dont-01, number = {draft-mattsson-tls-psk-ke-dont-dont-dont-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-mattsson-tls-psk-ke-dont-dont-dont/01/}, author = {John Preuß Mattsson}, title = {{Key Exchange Without Forward Secrecy is NOT RECOMMENDED}}, pagetotal = 6, year = 2021, month = may, day = 18, abstract = {Key exchange without forward secrecy enables passive monitoring. Massive pervasive monitoring attacks relying on key exchange without forward secrecy has been reported, and many more have likely happened without ever being reported. If key exchange without Diffie-Hellman is used, access to the long-term authentication keys enables a passive attacker to compromise past and future sessions. Entities can get access to long-term key material in different ways: physical attacks, hacking, social engineering attacks, espionage, or by simply demanding access to keying material with or without a court order. psk\_ke does not provide forward secrecy and is NOT RECOMMENDED. This document sets the IANA registration of psk\_ke to NOT RECOMMENDED.}, }