Re: [CFRG] [EXT] IETF WG Interest in AES-GCM-SST

Martin Thomson <mt@lowentropy.net> Thu, 04 April 2024 03:29 UTC

Return-Path: <mt@lowentropy.net>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C3FBC1519B4 for <cfrg@ietfa.amsl.com>; Wed, 3 Apr 2024 20:29:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.796
X-Spam-Level:
X-Spam-Status: No, score=-2.796 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="zlJr8V+0"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="UgXXMYsu"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LsXN-VRG70-7 for <cfrg@ietfa.amsl.com>; Wed, 3 Apr 2024 20:29:09 -0700 (PDT)
Received: from wfout2-smtp.messagingengine.com (wfout2-smtp.messagingengine.com [64.147.123.145]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E0A6AC1519AC for <cfrg@irtf.org>; Wed, 3 Apr 2024 20:29:09 -0700 (PDT)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailfout.west.internal (Postfix) with ESMTP id 8D4481C000F8; Wed, 3 Apr 2024 23:29:06 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute6.internal (MEProxy); Wed, 03 Apr 2024 23:29:06 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm3; t=1712201346; x=1712287746; bh=uUWMqQaDfh 6NSzo3mgHDIchBpEYTNlLPPyJKFqz5zvc=; b=zlJr8V+0T11pnOLlqq4poUbCHH BF83JsT/P/In2r7+OJI89oqVz41TPEsmDo9zOeM3rP6jsfU0EO8AneMOLF3CT7VO rx0ppu5xztTtBi1rbkUE0i/7eyNGkeWpnLaBzcagErU17m5LiCpfHrDWNET7o3OO D55yZsQXM80yqZ5/sq14Zn/qBHqOuwGWrPJhELxPdl5CH6GtmSRhJW1zqlvjfXxR txoA+FmX+WaAHumu+eSIXJzra42ZWsgUlcX9j87et0m+SiKDC2LIxNCTqSl5sIPC bcG/zEvkWMfNiUs1LyuaWIZJPE73aSJGxhYeUhmg3JCk0xKql8sIZSeUpBzw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm2; t=1712201346; x=1712287746; bh=uUWMqQaDfh6NSzo3mgHDIchBpEYT NlLPPyJKFqz5zvc=; b=UgXXMYsuyfYe0+8QShMBEdzJ06na4wjhT8qOThUedACs DgWiZiwCnxAkDt2GX2bXZu5J5fv243y9TWtubyj+qYwUS3JKrp48o9lqnNmOZGb/ NcyKQmIQsLGJ+xzKL38plfGRERDROEelY/W8LeOWtLwp65vP3PcL7NOLUlFQTN3p /sZrWBfV7fhcyZnZrVPQ07gDI9Z3ge/YN6yJUNyMl0Rnt6nNAYsUshTju3cIzDUe aC5UC5OWkaAAX3v04KR+eOVZARnK8e9AbbUmQs+fFqtSNcAHCFYaoNmuzuorUW7K xIG6Yt7CZlxtF8+lPrmGdmQrF9SaSExQuc20J9L+HQ==
X-ME-Sender: <xms:gR4OZgbJnD1vBq5GxwcK9ETcaAqQPO3vMenFjceb2DPILkYVP3LLOA> <xme:gR4OZrYX2-UfzdKQKPD6OgafTNb6XS6q2X2EBCn5O8esMveMqzsng4aQOWPHpfLFv Qq9kWlpw_FvjZClNOc>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvledrudefjedgjeduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvffutgesthdtredtreertdenucfhrhhomhepfdforghr thhinhcuvfhhohhmshhonhdfuceomhhtsehlohifvghnthhrohhphidrnhgvtheqnecugg ftrfgrthhtvghrnhepkeetueeikedtkeelfeekvefhkeffvedvvefgkefgleeugfdvjeej geffieegtdejnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrh homhepmhhtsehlohifvghnthhrohhphidrnhgvth
X-ME-Proxy: <xmx:gR4OZq_0vlz93wQauE7MyNyOZUcT0Tg7u9h2T-6kFunGLJeGoRlUtw> <xmx:gR4OZqrUWqVXIlhg53NmuHnzFLCdTYXZvLgtqAkYEEgkvXHlsJPAXg> <xmx:gR4OZroMubcGWuqYie3ugm7w71H-N39Pg78Ux0GciY2GB_Ti5ws0pQ> <xmx:gR4OZoQjmAPhDoWWFQgzZ6YNMTJwWlD_6QX4_aMP7OzLfgg-vQFgng> <xmx:gh4OZqX1Z_gm_3Goqp0oWakbBOT3xI8zohAY2oQK1Z6mbOaBMOqt__kv>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.nyi.internal (Postfix, from userid 501) id C60842340081; Wed, 3 Apr 2024 23:29:05 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.11.0-alpha0-333-gbfea15422e-fm-20240327.001-gbfea1542
MIME-Version: 1.0
Message-Id: <6d8e6be7-52c3-4aa2-b970-a9ed8f0ecc6d@betaapp.fastmail.com>
In-Reply-To: <BN0P110MB14192D55538E9115BDB9A28F903DA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
References: <CAKx+b+ZaqUfAQiLjkpWGgZAWRpVJYJtAm=v+-PVU1PMPP5Tu8Q@mail.gmail.com> <BN0P110MB14192D55538E9115BDB9A28F903DA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
Date: Thu, 04 Apr 2024 14:28:32 +1100
From: Martin Thomson <mt@lowentropy.net>
To: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>, Jonathan Lennox <jonathan.lennox42@gmail.com>, "cfrg@irtf.org" <cfrg@irtf.org>
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Ve40lMcIbEvW060v5YfU3XKpOGw>
Subject: Re: [CFRG] [EXT] IETF WG Interest in AES-GCM-SST
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://mailman.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://mailman.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Apr 2024 03:29:14 -0000

On Thu, Apr 4, 2024, at 00:56, Blumenthal, Uri - 0553 - MITLL wrote:
> Is AES-GCM-SST still failing catastrophically when nonce is re-used?

Of course.  But that isn't a problem for SRTP.

I am interested in the OCB vs. SST conversation and whether the media folks considered OCB.