Contact Details
essien.ge@philips.com
Section Number
2:3.YY3.4.1.3 Expected Actions
What is wrong
Currently the key used to encrypt the document is transmitted in plaintext. I'm not seeing in this way it brings any security improvement compared to simply transmit the document in plaintext.
Describe the solution you'd like
Understood it is inherent from SHL. However still suggest to include some way to encrypt the key, e.g. through the PKI material established in YY-1/2.
Or if not, at least add some security consideration to discuss this.
Relevant log output
Priority
{"Medium" => "Significant issue or clarification. Requires discussion, but should not lead to long debate."}
Code of Conduct
Contact Details
essien.ge@philips.com
Section Number
2:3.YY3.4.1.3 Expected Actions
What is wrong
Currently the key used to encrypt the document is transmitted in plaintext. I'm not seeing in this way it brings any security improvement compared to simply transmit the document in plaintext.
Describe the solution you'd like
Understood it is inherent from SHL. However still suggest to include some way to encrypt the key, e.g. through the PKI material established in YY-1/2.
Or if not, at least add some security consideration to discuss this.
Relevant log output
Priority
{"Medium" => "Significant issue or clarification. Requires discussion, but should not lead to long debate."}
Code of Conduct