Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
"David McGrew (mcgrew)" <mcgrew@cisco.com> Thu, 05 November 2015 13:31 UTC
Return-Path: <mcgrew@cisco.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 728BE1B2BCF; Thu, 5 Nov 2015 05:31:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.51
X-Spam-Level:
X-Spam-Status: No, score=-14.51 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K-2-LRswSCYJ; Thu, 5 Nov 2015 05:31:29 -0800 (PST)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CCEB1B2BCD; Thu, 5 Nov 2015 05:31:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=23482; q=dns/txt; s=iport; t=1446730289; x=1447939889; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=PaiyfXhJZeNEvnfb6cGDObsdqqt4ub6MsTmxtAqI1Kg=; b=LulafyyinAm2i4MVDDFV716PEvJrajsihcm+yYaEGLrwfxuXjUQt7/dl NZCdOCVduiL1jjYLtLYa8gq4LCUChkWFDyPstFlzlLf2jWs53ol+5tctJ lJfTn8dpwOqpvlgDJWGgD27YLt1VRSljlc5XIYf/9Kdjm68BzSNAkveJF w=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AOAgDxWDtW/4sNJK1egm5NU28GvgMBDYFeFwEJhXECHIESOBQBAQEBAQEBgQqENQEBAQMBAQEBIAoaJwsFBwQCAQgRBAEBAScDAgICHwYLFAkIAgQOBQiIEQMKCA2we4UahxANhDwBAQEBAQEBAQEBAQEBAQEBAQEBAQEUBItSglOCNYJtgUQFlkgBiy6BbYFhhD+OV4Ngg3EBHwEBQoIQAR2BVnKEGIEHAQEB
X-IronPort-AV: E=Sophos; i="5.20,247,1444694400"; d="scan'208,217"; a="44107503"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by rcdn-iport-4.cisco.com with ESMTP; 05 Nov 2015 13:31:28 +0000
Received: from XCH-RCD-003.cisco.com (xch-rcd-003.cisco.com [173.37.102.13]) by alln-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id tA5DVSZg005961 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 5 Nov 2015 13:31:28 GMT
Received: from xch-aln-004.cisco.com (173.36.7.14) by XCH-RCD-003.cisco.com (173.37.102.13) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Thu, 5 Nov 2015 07:31:27 -0600
Received: from xch-aln-004.cisco.com ([173.36.7.14]) by XCH-ALN-004.cisco.com ([173.36.7.14]) with mapi id 15.00.1104.000; Thu, 5 Nov 2015 07:31:27 -0600
From: "David McGrew (mcgrew)" <mcgrew@cisco.com>
To: Watson Ladd <watsonbladd@gmail.com>
Thread-Topic: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
Thread-Index: AQHRCqV+9XhITs3VfEqF6cfugvJKSJ6KT7QAgAHs7YCAAEw6gIABUImA//+lPSA=
Date: Thu, 05 Nov 2015 13:31:27 +0000
Message-ID: <909ecf3951a642e59ef5ae72222f2ca9@XCH-ALN-004.cisco.com>
References: <20151019193635.30765.20164.idtracker@ietfa.amsl.com> <CAM_a8JxB3FcfqSr8z2FUVxsY9Fw0kcAaJ8CHN+W4VY+5D_oyEQ@mail.gmail.com> <CACsn0cn=pZa4Yhhn4qojQN96=Jv6J1GU6JD4MKP5iHAFXn=RpA@mail.gmail.com> <362f4b9abe57495c902f9ccb968b3b7c@XCH-ALN-004.cisco.com> <CACsn0c=M4vx2nAS36Hyz9ouWa_aX136EgKo--TszJsqGW0D2iQ@mail.gmail.com>
In-Reply-To: <CACsn0c=M4vx2nAS36Hyz9ouWa_aX136EgKo--TszJsqGW0D2iQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.117.10.228]
Content-Type: multipart/alternative; boundary="_000_909ecf3951a642e59ef5ae72222f2ca9XCHALN004ciscocom_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/K9co4GoO8LzFnvTduUKonk67oWY>
Cc: "cfrg@ietf.org" <cfrg@ietf.org>, "internet-drafts@ietf.org" <internet-drafts@ietf.org>, "i-d-announce@ietf.org" <i-d-announce@ietf.org>
Subject: Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Nov 2015 13:31:32 -0000
Hi Watson,
-----Original Message-----
From: Watson Ladd [mailto:watsonbladd@gmail.com]
Sent: Thursday, November 05, 2015 7:25 AM
To: David McGrew (mcgrew)
Cc: Zooko Wilcox-OHearn; cfrg@ietf.org; internet-drafts@ietf.org; i-d-announce@ietf.org
Subject: Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
On Wed, Nov 4, 2015 at 5:50 PM, David McGrew (mcgrew) <mcgrew@cisco.com<mailto:mcgrew@cisco.com>> wrote:
> Hi Watson and Zooko,
>
>
> -----Original Message-----
> From: Cfrg [mailto:cfrg-bounces@irtf.org] On Behalf Of Watson Ladd
> Sent: Wednesday, November 04, 2015 6:48 AM
> To: Zooko Wilcox-OHearn
> Cc: cfrg@ietf.org<mailto:cfrg@ietf.org>; internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>; i-d-announce@ietf.org<mailto:i-d-announce@ietf.org>
> Subject: Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt
>
> On Tue, Nov 3, 2015 at 1:23 AM, Zooko Wilcox-OHearn
> <zooko@leastauthority.com<mailto:zooko@leastauthority.com>> wrote:
>> Dear folks:
>>
>> Is there a better way for me to register my objections to this scheme
>> than my earlier post to CFRG about it?
>
> To be clear: This scheme will fail in very nasty, very obvious ways
> anytime you have backups of your machine, or restart your VM, or crash
> at just the wrong moment.
>
> Section 10.1 documents some of the concerns that you raise and
> provides some guidance. Probably stronger guidance is needed; if you
> have suggestions, please let us know.
>
> Proposing it, and expecting it to be used widely, will inevitably lead
> to these problems on a mass scale.
>
> Hash based signatures are well suited for some applications, such as the
> long-term protection of firmware that is checked in embedded systems. In
> these cases postquantum security is essential, the verifier needs to
> be compact, and signing is a relatively rare operation.
How does the rarity of signing decrease the problems posed by backups?
It doesn't, as you already know, but rarity of signing makes state synchronization easier.
If anything, embedding implementations into hardware or ROM is likely to lead to lots of backups of the private key, and any restore will cause problems. There are workarounds, but they have costs with reducing the number of possible signatures.
Alternatives like SPHINCS are post quantum secure and do not have this extremely likely failure mode.
I agree that stateless signatures are also worth investigating.
>
> Is this really what we want to tell people to use?
>
> Like Winston Churchill said about democracy, they are the worst
> postquantum secure digital signatures, except for all the others.
>
> For sure the issue of synchronization of state in hash based
> signatures schemes is a major issue, and there might be scenarios where they will never
> be appropriate, such as VM environments in which VMs are cloned. It may be
> the case that these types of signatures need to have a different interface
> that would better ensure the security of implementations. But in any case,
> given their postquantum security and solid theoretical foundations,
> they deserve to be studied more to see what their limits are.
It's not about the security of an implementation, but a deployment.
Back up your computer? You've revealed your secret key. Ensure HVM failures won't render your hardware unupdatable? You've revealed your secret key. Does Cisco really think that a single point of failure for updating firmware is acceptable?
Like many other vendors, Cisco is looking into postquantum security, including hash based signatures with stateful components.
The CFRG is not a CRYPTO reviewer panel. Publishing this draft will lead to it being used in products.
This is total BS. The IRTF chartered CFRG to be a “forum for discussing and analyzing general cryptographic aspects of security protocols, and to offer guidance on the use of emerging mechanisms and new uses of existing mechanisms”.
David
>
> David
>
>>
>> Regards,
>>
>> Zooko
>>
>> _______________________________________________
>> Cfrg mailing list
>> Cfrg@irtf.org<mailto:Cfrg@irtf.org>
>> https://www.irtf.org/mailman/listinfo/cfrg
>
>
>
> --
> "Man is born free, but everywhere he is in chains".
> --Rousseau.
>
> _______________________________________________
> Cfrg mailing list
> Cfrg@irtf.org<mailto:Cfrg@irtf.org>
> https://www.irtf.org/mailman/listinfo/cfrg
>
--
"Man is born free, but everywhere he is in chains".
--Rousseau.
- [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.txt internet-drafts
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Zooko Wilcox-OHearn
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Watson Ladd
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Panos Kampanakis (pkampana)
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Andy Lutomirski
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… David McGrew (mcgrew)
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Watson Ladd
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… David McGrew (mcgrew)
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… A.Huelsing
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Watson Ladd
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… Russ Housley
- Re: [Cfrg] I-D Action: draft-mcgrew-hash-sigs-03.… A.Huelsing