| Agreed. It looks as though the researchers saw that as a possibility too: "It is possible to temporarily mitigate the flaw by implementing the following workaround: Researchers have demonstrated that ITP can be operated over TLS/DTLS, using certificate-based authentication to ensure the security and integrity of the protocol." I don't really understand why this is only a "temporary mitigation", though, rather than a reasonable long-term solution. Can anyone enlighten me? Maybe the extra technical complexity of setting up these certificates is deemed too great, and the likelihood of people getting it wrong too high? |