Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt

"David McGrew (mcgrew)" <mcgrew@cisco.com> Wed, 04 November 2015 22:50 UTC

Return-Path: <mcgrew@cisco.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 27E6F1B35D6; Wed, 4 Nov 2015 14:50:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.51
X-Spam-Level:
X-Spam-Status: No, score=-14.51 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DjUB13bsALpv; Wed, 4 Nov 2015 14:50:04 -0800 (PST)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 246891B35D2; Wed, 4 Nov 2015 14:50:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8700; q=dns/txt; s=iport; t=1446677404; x=1447887004; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=VfijA3nYHbLCDaBUkdxEwjlx8N0aoyfjjRAkW4EDL3E=; b=aCm8+ya6UZQdcK4aJFSan3i9u81eO7sTZrEuJBsJaShPPXNeYLDUznQc S9RBN7TeQ7tmY4+OjXXL4hgA9m6IQnhnNaGKk84ZnpXIsRhxlxZuZDU9l IHzZbEYlIJH4Mf4cShgPUVmLxa73eM5jqcEMZ/TyPr0RtJtxQ9GQoVUQP E=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AcAgA3ijpW/5hdJa1egm5NU28GhA65XwENgV4XAQmFcQKBPTgUAQEBAQEBAYEKhDUBAQEDAQEBASpBCwUHBAIBCBEEAQEBJwcnCxQJCAIEAQ0FCIgeCA3CHwEBAQEBAQEBAQEBAQEBAQEBAQEBARQEi1KFCIQwBZZIAY0bgWGEP5I2g3EBHwEBQoIQAR2BVnKELYEHAQEB
X-IronPort-AV: E=Sophos; i="5.20,245,1444694400"; d="scan'208,217"; a="46872749"
Received: from rcdn-core-1.cisco.com ([173.37.93.152]) by rcdn-iport-2.cisco.com with ESMTP; 04 Nov 2015 22:50:03 +0000
Received: from XCH-RCD-003.cisco.com (xch-rcd-003.cisco.com [173.37.102.13]) by rcdn-core-1.cisco.com (8.14.5/8.14.5) with ESMTP id tA4Mo3LZ017543 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 4 Nov 2015 22:50:03 GMT
Received: from xch-aln-004.cisco.com (173.36.7.14) by XCH-RCD-003.cisco.com (173.37.102.13) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Wed, 4 Nov 2015 16:50:03 -0600
Received: from xch-aln-004.cisco.com ([173.36.7.14]) by XCH-ALN-004.cisco.com ([173.36.7.14]) with mapi id 15.00.1104.000; Wed, 4 Nov 2015 16:50:02 -0600
From: "David McGrew (mcgrew)" <mcgrew@cisco.com>
To: Watson Ladd <watsonbladd@gmail.com>, Zooko Wilcox-OHearn <zooko@leastauthority.com>
Thread-Topic: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
Thread-Index: AQHRCqV+9XhITs3VfEqF6cfugvJKSJ6KT7QAgAHs7YCAAEw6gA==
Date: Wed, 04 Nov 2015 22:50:02 +0000
Message-ID: <362f4b9abe57495c902f9ccb968b3b7c@XCH-ALN-004.cisco.com>
References: <20151019193635.30765.20164.idtracker@ietfa.amsl.com> <CAM_a8JxB3FcfqSr8z2FUVxsY9Fw0kcAaJ8CHN+W4VY+5D_oyEQ@mail.gmail.com> <CACsn0cn=pZa4Yhhn4qojQN96=Jv6J1GU6JD4MKP5iHAFXn=RpA@mail.gmail.com>
In-Reply-To: <CACsn0cn=pZa4Yhhn4qojQN96=Jv6J1GU6JD4MKP5iHAFXn=RpA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.117.10.228]
Content-Type: multipart/alternative; boundary="_000_362f4b9abe57495c902f9ccb968b3b7cXCHALN004ciscocom_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/95U_M65-6T5OAACOyZYWxQR0Q84>
Cc: "cfrg@ietf.org" <cfrg@ietf.org>, "internet-drafts@ietf.org" <internet-drafts@ietf.org>, "i-d-announce@ietf.org" <i-d-announce@ietf.org>
Subject: Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Nov 2015 22:50:06 -0000

Hi Watson and Zooko,


      -----Original Message-----
      From: Cfrg [mailto:cfrg-bounces@irtf.org] On Behalf Of Watson Ladd
      Sent: Wednesday, November 04, 2015 6:48 AM
      To: Zooko Wilcox-OHearn
      Cc: cfrg@ietf.org; internet-drafts@ietf.org; i-d-announce@ietf.org
      Subject: Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt

      On Tue, Nov 3, 2015 at 1:23 AM, Zooko Wilcox-OHearn <zooko@leastauthority.com<mailto:zooko@leastauthority.com>> wrote:
      > Dear folks:
      >
      > Is there a better way for me to register my objections to this scheme
      > than my earlier post to CFRG about it?

      To be clear: This scheme will fail in very nasty, very obvious ways anytime you have backups of your machine, or restart your VM, or crash at just the wrong moment.

Section 10.1 documents some of the concerns that you raise and provides some guidance.  Probably stronger guidance is needed; if you have suggestions, please let us know.

      Proposing it, and expecting it to be used widely, will inevitably lead to these problems on a mass scale.

Hash based signatures are well suited for some applications, such as the long-term protection of firmware that is checked in embedded systems.   In these cases postquantum security is essential, the verifier needs to be compact, and signing is a relatively rare operation.    For other applications they are less well suited.

      Is this really what we want to tell people to use?

Like Winston Churchill said about democracy, they are the worst postquantum secure digital signatures, except for all the others.

For sure the issue of synchronization of state in hash based signatures schemes is a major issue, and there might be scenarios where they will never be appropriate, such as VM environments in which VMs are cloned.   It may be the case that these types of signatures need to have a different interface that would better ensure the security of implementations.   But in any case, given their postquantum security and solid theoretical foundations, they deserve to be studied more to see what their limits are.

David

      >
      > Regards,
      >
      > Zooko
      >
      > _______________________________________________
      > Cfrg mailing list
      > Cfrg@irtf.org<mailto:Cfrg@irtf.org>
      > https://www.irtf.org/mailman/listinfo/cfrg



--
"Man is born free, but everywhere he is in chains".
--Rousseau.

_______________________________________________
Cfrg mailing list
Cfrg@irtf.org<mailto:Cfrg@irtf.org>
https://www.irtf.org/mailman/listinfo/cfrg