Re: [Cfrg] Requesting removal of CFRG co-chair
William Whyte <wwhyte@securityinnovation.com> Fri, 20 December 2013 19:04 UTC
Return-Path: <wwhyte@securityinnovation.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F94B1ADEBA for <cfrg@ietfa.amsl.com>; Fri, 20 Dec 2013 11:04:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.379
X-Spam-Level:
X-Spam-Status: No, score=-1.379 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GuaFNBHBOrch for <cfrg@ietfa.amsl.com>; Fri, 20 Dec 2013 11:04:43 -0800 (PST)
Received: from mail-qc0-x22b.google.com (mail-qc0-x22b.google.com [IPv6:2607:f8b0:400d:c01::22b]) by ietfa.amsl.com (Postfix) with ESMTP id EADFA1ADF9B for <cfrg@ietf.org>; Fri, 20 Dec 2013 11:04:42 -0800 (PST)
Received: by mail-qc0-f171.google.com with SMTP id c9so2576819qcz.16 for <cfrg@ietf.org>; Fri, 20 Dec 2013 11:04:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=securityinnovation.com; s=google; h=from:references:in-reply-to:mime-version:thread-index:date :message-id:subject:to:content-type; bh=NH8YWsXuG78cNLd4DwWX5dLroy0MFV5FDWMzGpXRGRE=; b=NKt/9Gdnevi0GyzIBEyixclIsnS1z1x25kmSCUmdRNk4/gTa4Uh4/uTl5C4fE0PrIl RODWpotzh8apGQEn39GX9dvsfH3TwCSyiaRuN2lVJji14RY+4KndIrHEUNSAD9k7ozWF 2y1fYrlHSpOAWalMMq2RKA4yIicdPxgo9MfPA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:references:in-reply-to:mime-version :thread-index:date:message-id:subject:to:content-type; bh=NH8YWsXuG78cNLd4DwWX5dLroy0MFV5FDWMzGpXRGRE=; b=FcXnaxLmxYncru+CUd2FBkTH1HwIsuUxWo4sqVsJ3WqfE+RkcKZGyEdicnboh92H6A akl1DIGkBZsfghzym78YyBsnGBh5AMrDKwBkAx5QNI75BWiJR8n3aKQXu9k3A6UmBKNn iNIT8kLYOA/FKJfp2DcOnzm7bPnYctBJWG+9v5/RmSqp/cTNuD1enQv+Vz0rg7t3g61j S2Wc2pL+FKypkMYvCgH7TbLM9KUSHNq1Qm9r5aFRTlGQSyanVRof87dVi7cIBhnyqJT8 amLfYkPND/K6CG8fUNKLBuzW6aHy3BAuuDdhoBVuMfzYnKo7+ORe/7uu9pUlaTC30rou QZrA==
X-Gm-Message-State: ALoCoQmeVqKXJIIhu111JKBe2b2ZqQrK+dvOceEOXuz0zNU7G5NicERJ1tIE6io9PbDAwTusWVDk
X-Received: by 10.229.65.130 with SMTP id j2mr17107629qci.6.1387566280513; Fri, 20 Dec 2013 11:04:40 -0800 (PST)
From: William Whyte <wwhyte@securityinnovation.com>
References: <CAGZ8ZG2f9QHX40RcB8aajWvEfG0Gh_uewu2Rq7bQGHYNx6cOmw@mail.gmail.com>
In-Reply-To: <CAGZ8ZG2f9QHX40RcB8aajWvEfG0Gh_uewu2Rq7bQGHYNx6cOmw@mail.gmail.com>
MIME-Version: 1.0
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQIQdep8VG0rr2PaqKp4agice/BVd5nacRoA
Date: Fri, 20 Dec 2013 14:04:41 -0500
Message-ID: <af4ecf834566c57b1ec5699484a95056@mail.gmail.com>
To: Trevor Perrin <trevp@trevp.net>, cfrg@ietf.org
Content-Type: text/plain; charset="ISO-8859-1"
Subject: Re: [Cfrg] Requesting removal of CFRG co-chair
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Dec 2013 19:04:45 -0000
I agree. It's appropriate for Kevin to be able to contribute, just as it's appropriate for any individual to be able to contribute, but it's not appropriate for any NSA employee to have a role of responsibility in a crypto standards group, especially a group developing standards to be used worldwide. William -----Original Message----- From: Cfrg [mailto:cfrg-bounces@irtf.org] On Behalf Of Trevor Perrin Sent: Friday, December 20, 2013 11:02 AM To: irtf-chair@irtf.org; iab@iab.org; cfrg@ietf.org Subject: [Cfrg] Requesting removal of CFRG co-chair Dear IRTF Chair, IAB, and CFRG: I'd like to request the removal of Kevin Igoe from CFRG co-chair. The Crypto Forum Research Group is chartered to provide crypto advice to IETF Working Groups. As CFRG co-chair for the last 2 years, Kevin has shaped CFRG discussion and provided CFRG opinion to WGs. Kevin's handling of the "Dragonfly" protocol raises doubts that he is performing these duties competently. Additionally, Kevin's employment with the National Security Agency raises conflict-of-interest concerns. Dragonfly Background ---- Dragonfly is a "Password-Authenticated Key Exchange" protocol (or "PAKE"). Dragonfly was proposed to CFRG 2 years ago [PROPOSAL]. Compared to better-known PAKEs, Dragonfly has no security proof, a lack of extensive security analysis, nonfunctional complications added for IPR reasons, and some security issues [REVIEW]. Dragonfly became a hot topic recently when the TLS WG disputed CFRG's alleged report that Dragonfly was "satisfactory", as well as disputing that this report reflected CFRG consensus [TLS_1]. After extensive criticism of Dragonfly, the TLS WG ceased work on a Dragonfly extension [TLS_2]. NSA Background ---- The National Security Agency ("NSA") is a U.S. Intelligence Agency which is believed to devote considerable resources to: - "Influence policies, standards and specifications for commercial public key technologies" - "Shape the worldwide cryptography marketplace to make it more tractable to advanced cryptanalytic capabilities" [BULLRUN] While much is unknown about these activities, the NSA is known to have placed a "back door" in a NIST standard for random number generation [ECDRBG]. A recent report from the President's Review Group recommends that the NSA: - "fully support and not undermine efforts to create encryption standards" - "not in any way subvert, undermine, weaken, or make vulnerable generally available commercial software" [PRESIDENTS] This suggests the NSA is currently behaving contrary to the recommendations. Reasons for requesting Kevin's removal ---- 1) Kevin has provided the *ONLY* positive feedback for Dragonfly that can be found on the CFRG mailing list or meeting minutes. The contrast between Kevin's enthusiasm and the group's skepticism is striking [CFRG_SUMMARY]. It's unclear what this enthusiasm is based on. There's no record of Kevin making any effort to understand Dragonfly's unusual structure, compare it to alternatives, consider possible use cases, or construct a formal security analysis. 2) Twice Kevin suggested a technique for deriving the Dragonfly password-based element which would make the protocol easy to break [IGOE_1, IGOE_2]. He also endorsed an ineffective attempt to avoid timing attacks by adding extra iterations to one of the loops [IGOE_3, IGOE_4]. These are surprising mistakes from an experienced cryptographer. 3) Kevin's approval of Dragonfly to the TLS WG misrepresented CFRG consensus, which was skeptical of Dragonfly [CFRG_SUMMARY]. 4) Kevin's NSA affiliation raises unpleasant but unavoidable questions regarding these actions. It's entirely possible these are just mistakes by a novice chair who lacks experience in a particular sort of protocol and is being pressured by IETF participants to endorse something. But it's hard to escape an impression of carelessness and unseriousness in Kevin's work. One wonders whether the NSA is happy to preside over this sort of sloppy crypto design. While that's of course speculation, it remains baffling that an experienced cryptographer would champion such a shoddy protocol. The CFRG chairs have been silent for months, and haven't responded to attempts to clarify this. Conclusion ---- The position of CFRG chair (or co-chair) is a role of crucial importance to the IETF community. The IETF is in desperate need of trustworthy crypto guidance from parties who are above suspicion. I encourage the IAB and IRTF to replace Kevin Igoe with someone who can provide this. Thanks for considering this request. Trevor [PROPOSAL] http://www.ietf.org/mail-archive/web/cfrg/current/msg03044.html [REVIEW] http://www.ietf.org/mail-archive/web/cfrg/current/msg03537.html [TLS_1] http://www.ietf.org/mail-archive/web/tls/current/msg10819.html [TLS_2] http://www.ietf.org/mail-archive/web/tls/current/msg10993.html [BULLRUN] http://www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-camp aign-against-encryption.html [ECDRBG] http://bits.blogs.nytimes.com/2013/09/10/government-announces-steps-to-res tore-confidence-on-encryption-standards/ [PRESIDENTS] http://www.whitehouse.gov/sites/default/files/docs/2013-12-12_rg_final_rep ort.pdf [CFRG_SUMMARY] http://www.ietf.org/mail-archive/web/cfrg/current/msg03545.html [IGOE_1] http://www.ietf.org/mail-archive/web/cfrg/current/msg03047.html [IGOE_2] http://www.ietf.org/mail-archive/web/cfrg/current/msg03258.html [IGOE_3] http://www.ietf.org/mail-archive/web/cfrg/current/msg03262.html [IGOE_4] http://www.ietf.org/mail-archive/web/cfrg/current/msg03264.html _______________________________________________ Cfrg mailing list Cfrg@irtf.org http://www.irtf.org/mailman/listinfo/cfrg
- [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair William Whyte
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Eggert, Lars
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Watson Ladd
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Daniel Kahn Gillmor
- Re: [Cfrg] Requesting removal of CFRG co-chair Hilarie Orman
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Daniel Kahn Gillmor
- Re: [Cfrg] Requesting removal of CFRG co-chair Paul Lambert
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Watson Ladd
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Adam Back
- Re: [Cfrg] Requesting removal of CFRG co-chair Eggert, Lars
- Re: [Cfrg] Requesting removal of CFRG co-chair Mike Simpson
- Re: [Cfrg] Requesting removal of CFRG co-chair Watson Ladd
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Robert Ransom
- Re: [Cfrg] Requesting removal of CFRG co-chair Adam Back
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair Natanael
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair William Whyte
- Re: [Cfrg] Requesting removal of CFRG co-chair Henrick Hellström
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair John Viega
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Richard Barnes
- Re: [Cfrg] Requesting removal of CFRG co-chair John Bradley
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Richard Barnes
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair John Viega
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair John Viega
- Re: [Cfrg] Requesting removal of CFRG co-chair Watson Ladd
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Brian Weis
- Re: [Cfrg] Requesting removal of CFRG co-chair Tom Ritter
- Re: [Cfrg] Requesting removal of CFRG co-chair Brian Weis
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] CFRG and thwarting pervasive montoring Paul Lambert
- Re: [Cfrg] Requesting removal of CFRG co-chair Henrick Hellström
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Nikos Mavrogiannopoulos
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Watson Ladd
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Robert Ransom
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair Paul Hoffman
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- Re: [Cfrg] Requesting removal of CFRG co-chair idontneedcoffee
- Re: [Cfrg] Requesting removal of CFRG co-chair Alyssa Rowan
- Re: [Cfrg] Requesting removal of CFRG co-chair Yoav Nir
- Re: [Cfrg] Requesting removal of CFRG co-chair Eggert, Lars
- Re: [Cfrg] Requesting removal of CFRG co-chair idontneedcoffee
- Re: [Cfrg] Requesting removal of CFRG co-chair Stephen Farrell
- Re: [Cfrg] Requesting removal of CFRG co-chair Tao Effect
- [Cfrg] CFRG and thwarting pervasive montoring Paul Hoffman
- Re: [Cfrg] CFRG and thwarting pervasive montoring Stephen Farrell
- Re: [Cfrg] CFRG and thwarting pervasive montoring Watson Ladd
- Re: [Cfrg] CFRG and thwarting pervasive montoring Paul Hoffman
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair John Bradley
- [Cfrg] misuse-resistant AEAD (was: Re: CFRG and t… David McGrew
- Re: [Cfrg] misuse-resistant AEAD (was: Re: CFRG a… Watson Ladd
- Re: [Cfrg] misuse-resistant AEAD David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] misuse-resistant AEAD (was: Re: CFRG a… Dan Harkins
- Re: [Cfrg] misuse-resistant AEAD (was: Re: CFRG a… Watson Ladd
- Re: [Cfrg] misuse-resistant AEAD (was: Re: CFRG a… Dan Harkins
- Re: [Cfrg] misuse-resistant AEAD David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Scott Fluhrer (sfluhrer)
- [Cfrg] changes to hunt-and-peck algorithm (Re: Re… David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] Requesting removal of CFRG co-chair Dan Harkins
- Re: [Cfrg] changes to hunt-and-peck algorithm (Re… Trevor Perrin
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair Daniel Kahn Gillmor
- Re: [Cfrg] Requesting removal of CFRG co-chair David McGrew
- Re: [Cfrg] Requesting removal of CFRG co-chair dan
- Re: [Cfrg] Requesting removal of CFRG co-chair Daniel Kahn Gillmor