On the contrary, it seems to be fairly decent timing. Since it draws attention to the issue of formal security in TLS. The formal proofs he refers to have caveats either 1) they use actually secure asymmetric crypto whereas TLS does not or 2) assume both that all parts work correctly in tandem and have some strange assumptions.
The fact that someone has vulnerability only goes to show you that we probably need to do more work both with the proofs and changing TLS so its easier to proof. This is possibly the third time that an ignored, "academic crypto issue' has broken TLS. This is of course assuming that they have a protocol flaw and not an implementation one.
Comments
On the contrary, it seems to be fairly decent timing. Since it draws attention to the issue of formal security in TLS. The formal proofs he refers to have caveats either 1) they use actually secure asymmetric crypto whereas TLS does not or 2) assume both that all parts work correctly in tandem and have some strange assumptions.
The fact that someone has vulnerability only goes to show you that we probably need to do more work both with the proofs and changing TLS so its easier to proof. This is possibly the third time that an ignored, "academic crypto issue' has broken TLS. This is of course assuming that they have a protocol flaw and not an implementation one.