Re: [Cfrg] adopting Argon2 as a CFRG document

Mike Hamburg <mike@shiftleft.org> Fri, 22 January 2016 19:20 UTC

Return-Path: <mike@shiftleft.org>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A038B1B29EC for <cfrg@ietfa.amsl.com>; Fri, 22 Jan 2016 11:20:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.556
X-Spam-Level: *
X-Spam-Status: No, score=1.556 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HOST_EQ_D_D_D_D=0.765, FH_HOST_EQ_D_D_D_DB=0.888, HELO_MISMATCH_ORG=0.611, HOST_MISMATCH_NET=0.311, HTML_MESSAGE=0.001, RDNS_DYNAMIC=0.982, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cdzwd6RkBaW4 for <cfrg@ietfa.amsl.com>; Fri, 22 Jan 2016 11:20:47 -0800 (PST)
Received: from astral.shiftleft.org (199-241-202-70.PUBLIC.monkeybrains.net [199.241.202.70]) by ietfa.amsl.com (Postfix) with ESMTP id 4E9071AD0A0 for <Cfrg@irtf.org>; Fri, 22 Jan 2016 11:20:47 -0800 (PST)
Received: from [10.184.148.249] (unknown [209.36.6.242]) (Authenticated sender: mike) by astral.shiftleft.org (Postfix) with ESMTPSA id 2403EA0DB4; Fri, 22 Jan 2016 11:20:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=shiftleft.org; s=sldo; t=1453490447; bh=eeR7jKDmX8XI7IlDl8bF8HmhQq1/HW5hGk1hXqWY/Zg=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=bInunGJ5uYEnyVarIMOM2nwJ2DUGvudzjbJf0Lw85u0jVIjwey7AnllYs24wld9KT IMNGn8Mhz4NBmulpbLtMyv7+xuLtEm3ffgHAo7y3Cwoe2epj0lT/ABfH+M2s1CFZC/ bqJEPBpm4TbMe0spGlDgWN2TckJWIZgpbXl9AfDw=
Content-Type: multipart/alternative; boundary="Apple-Mail=_E6BBDE0A-01B0-4144-A16E-CA3D762E5469"
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
From: Mike Hamburg <mike@shiftleft.org>
In-Reply-To: <D2C82E57.60B44%kenny.paterson@rhul.ac.uk>
Date: Fri, 22 Jan 2016 11:20:46 -0800
Message-Id: <6D05C894-4D0D-4089-B4C1-40DF4FDE6C63@shiftleft.org>
References: <D2C82E57.60B44%kenny.paterson@rhul.ac.uk>
To: "Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk>
X-Mailer: Apple Mail (2.3112)
X-Virus-Scanned: clamav-milter 0.98.7 at astral
X-Virus-Status: Clean
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/V83N099LlKp1Sy4gEGz0c_IB3Bs>
Cc: "cfrg@irtf.org" <Cfrg@irtf.org>
Subject: Re: [Cfrg] adopting Argon2 as a CFRG document
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Jan 2016 19:20:48 -0000

We might want to hold off on Argon2 — at least on finalizing it — until the team has
responded to (and hopefully mitigated) the issues mentioned at
https://eprint.iacr.org/2016/027 <https://eprint.iacr.org/2016/027>.  Essentially the problem is that Argon2 can be computed
in less space than advertised.  The team said that they are planning a response, cf
http://permalink.gmane.org/gmane.comp.security.phc/3606 <http://permalink.gmane.org/gmane.comp.security.phc/3606>

Cheers,
— Mike

> On Jan 22, 2016, at 11:10 AM, Paterson, Kenny <Kenny.Paterson@rhul.ac.uk> wrote:
> 
> Dear CFRG,
> 
> Having received limited feedback either way from the group (specifically,
> one voice in favour), the CFRG chairs have decided to adopt
> https://tools.ietf.org/html/draft-josefsson-argon2-00 as a CFRG document.
> 
> If you have objections or concerns, please reply to this email or directly
> to CFRG chairs.
> 
> Sincerely,
> 
> Kenny Paterson (for the chairs)
> 
> 
> On 06/11/2015 11:47, "Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk> wrote:
> 
>> Hi Stephen,
>> 
>> Yes, the chairs are amenable to this. We've been keeping an eye on the
>> password hashing competition and were planning a work item in this area.
>> 
>> Any comments from the group, either supporting or objecting to us adopting
>> this draft in the RG?
>> 
>> Cheers,
>> 
>> Kenny 
>> 
>> (for the chairs)
>> 
>> On 06/11/2015 02:18, "Cfrg on behalf of Stephen Farrell"
>> <cfrg-bounces@irtf.org on behalf of stephen.farrell@cs.tcd.ie> wrote:
>> 
>>> 
>>> The password hashing competition has a winner and some folks
>>> in the openpgp wg are interested in using that winner. I guess
>>> this might be better processed via cfrg if folks are amenable
>>> to that.
>>> 
>>> Thanks,
>>> S.
> 
> _______________________________________________
> Cfrg mailing list
> Cfrg@irtf.org
> https://www.irtf.org/mailman/listinfo/cfrg