Re: [CFRG] Attack on a Real World SPAKE2 Implementation Sun, 09 May 2021 19:03 UTC
Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 2B0423A1B42 for <>; Sun, 9 May 2021 12:03:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: 0.002
X-Spam-Status: No, score=0.002 tagged_above=-999 required=5 tests=[SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 3eUle7ZVnGS3 for <>; Sun, 9 May 2021 12:03:00 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 1DDF33A1B3D for <>; Sun, 9 May 2021 12:02:59 -0700 (PDT)
Received: from ([]) by (mreueus003 []) with ESMTPSA (Nemesis) id 0MS4Ue-1m4bsX0G0g-00T9HJ for <>; Sun, 09 May 2021 21:02:59 +0200
Date: Sun, 09 May 2021 14:02:58 -0500
Message-ID: <>
In-Reply-To: <>
References: <> <> <> <>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.4-Rev22
X-Originating-Client: open-xchange-appsuite
X-Provags-ID: V03:K1:gwO4QFtVWB13CMtOSU5GBGRJ5K298DrpsYOqZe4FLuEfBjYhHfc k9SnNXyp8ivIvrvJfakRaoDMP+t4nVIfPVEgATNOzPb45AxMulzF919mDHrxt4DbXUqj9U+ LDmMgJDh8R7eaeKTR7p5ZAB/X6/bnE29ksmG8MjBw6TOEoX+0Npt73AOMr+gjBxa8V8iDBI vPtGtVRIyp0NF2rzES+Sw==
X-UI-Out-Filterresults: notjunk:1;V03:K0:kXQwYs5AnMQ=:l4M3JlKNTLmcQp4oYU/sPN 5XM/JtIvqkpQbCYMmFyYaN5iR7/JVunk6DQ0WbTFdDRQxlr0Fx5arNlWY21x8MnHushbH/fW6 wytrxrxl6+RHqfqyOY4jfnnxvbZUbHEn5XE1olU/OOyYVST4SZBPn+9vUCXMnWH5UD0w6ckJr CNzzFhjMWWABvBw885WMykueOUwmGMAidf8qe5YcVsWYicWqkdY2zz2BqHe1CK7ouPsEx+gH+ mDwdEscJHz1dUeqcz8Slr/yfHDiK+JpTiMryq/eNJnUd7cSW2QyECnDkZkNjjGVa2kh6MdYew yXMbt56FJxMhXVYD7ESMvVFuD3Ao57M14SdJZRcHnQXkE52eMmChOry8yoPScTcREAKQKqrTu 0pHj6fVUos0C/QvwoNI0YSMjYzpnqBN97fugL9QPGUJsc2WyIXnQHm47oKnheq3gykIsMSQum CRDniiZGJ4haYHf56FTxCn6s7s1kALvW8j6ckujWUpuBqeeyF0xUqbMiz6lrZdBDaicAL7NVi i/tvhPPsU+Hty3JzrEUAWY=
Archived-At: <>
Subject: Re: [CFRG] Attack on a Real World SPAKE2 Implementation
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Sun, 09 May 2021 19:03:05 -0000
By the way, they state where the algorithm details came from "This protocol is derived from Dan Boneh and Victor Shoup's cryptography book [] (pg 789, 'PAKE2 protocol')." So we should look at that to see how to improve descriptions. I think it's really people not knowing that "hash to curve" or "a random point on the curve" are not normal things and very important. I know of someone who read about "hash to curve" in I think OPAQUE and thought that it was "H(value)*G". So we need to make special notes on these things. > On 05/09/2021 11:05 AM Björn Haase <> wrote: > > > Hello All, > > > > I think we should be be careful with biased wordings such as "sharing the blame" and assumptions such as "snake oil" which implies fraudulent intentions. > IMO, we just don't know all of the details and it might be more constructive not to speculate too much. > > (When writing this: Even though my professional experience taught me to never under-estimate the power of foolishness, I think that it should be considered to be truly remarkable how many things have gone wrong here simultaneously. ) > > For the same reason, I don't think that one should be careful of "blaming" the authors of the SPAKE2 for anything that has gone wrong here. > Regarding possible improvements of the draft I still would like to come up with a suggestion: > > What about adding a clear and *mandatory* specification for conforming implementations of SPAKE2 on any curve on how to generate the "nothing upon my sleeve" inputs M,N? > > I would recommend mandating a procedure that refers to the current draft version of the h2c draft as it is today. > > Alternatively, if one would like to avoid references to the h2c draft (in order to make M,N independent of possible future changes in the h2c draft), one could consider using a specification in the style of appendix A in, where similar "nothing upon my sleeve" points "A, C" were needed. > At any rate, I believe that there seems to be need for a mandatory trustworthy way for generating M, N for *any* curve. > > Yours, > Björn > P.S.: > Actually, I just noticed that its not really explicit how the points M, N in the current SPAKE2 draft 18 are calculated for the curves where test vectors are provided. I presume that the uniform h2c map was used for the given seed inputs? > > > Am 08.05.2021 um 01:51 schrieb Filippo Valsorda: > > > 2021-05-07 04:17 GMT-04:00 Peter Gutmann <>: > > > > > Ruben Gonzalez <> writes: > > > > > > > > > > > > >We did not attack SPAKE2 directly, but a faulty implementation. > > > > > > > > > > > > Nice work! This is an example of what I once referred to as second-order > > > > > > snake oil crypto, good crypto applied badly (first-order is bad crypto). > > > > > > > > > Snake oil is fraudulent. This is a broken implementation, for which specification authors should at least consider sharing the blame. How did the spec fail the implementers, who presumably were not trying to implement something in a broken way? > > > > > > > > (I know, I know, SPAKE2 is a draft, not an RFC! But it's been a draft for almost 7 years, and at some point people need to implement stuff.) > > > > > > > > _______________________________________________ > > CFRG mailing list > > > > > > > _______________________________________________ CFRG mailing list
- [CFRG] Attack on a Real World SPAKE2 Implementati… Ruben Gonzalez
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Peter Gutmann
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… steve
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Dan Harkins
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Filippo Valsorda
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… steve
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Watson Ladd
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Björn Haase
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… steve
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Loup Vaillant-David
- Re: [CFRG] Attack on a Real World SPAKE2 Implemen… Filippo Valsorda
- [CFRG] Modifying SPAKE2 draft for more curves (wa… Watson Ladd
- Re: [CFRG] Modifying SPAKE2 draft for more curves… Hao, Feng
- Re: [CFRG] Modifying SPAKE2 draft for more curves… Hao, Feng