Re: [CFRG] HPKE: final call for objections on the changes

Christopher Wood <caw@heapingbits.net> Thu, 05 August 2021 14:29 UTC

Return-Path: <caw@heapingbits.net>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8159B3A142C for <cfrg@ietfa.amsl.com>; Thu, 5 Aug 2021 07:29:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=heapingbits.net header.b=I4N1LXeN; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=B4FhQfW1
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0M8eZuQajbKN for <cfrg@ietfa.amsl.com>; Thu, 5 Aug 2021 07:29:42 -0700 (PDT)
Received: from wout2-smtp.messagingengine.com (wout2-smtp.messagingengine.com [64.147.123.25]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0DB43A1429 for <cfrg@irtf.org>; Thu, 5 Aug 2021 07:29:42 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 21CCE3200936 for <cfrg@irtf.org>; Thu, 5 Aug 2021 10:29:42 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute5.internal (MEProxy); Thu, 05 Aug 2021 10:29:42 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=heapingbits.net; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type; s=fm2; bh=pDYhoTs30ht1rC0Yo2i9c88/drzEMyV Iy8VmKtI9YQ8=; b=I4N1LXeN6HjVcst2giY3+nzkrGfEsE6N/0RoOBz4l3iLdxd u56l9ALq+ZwgYVW6PXjTiP/RZpRdM/euYuYRB5cmvXTtL+ykLIRFX6HGV1ydVk+e +rxZ/AmRKfJgaDtjHHCER8InxsdFyFQJLHFzsc0H9IYCsZriHe5MTjao1JvVU9LQ OPrHDzUGaPgDNnk67PG9DTjOfopdNM/6r0s+ov1WbXuV+a93hXx6k8gbAxG5edIS MilS3U/OpawvfKKjSzagulYdwItCX+HS0tZNDY0Z9M5EQyKIOnr6MjT1xdp1R2Wx 61QXaj9dWvxx96+aPIVwmzVjsoz7sgO8QNgqsJA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; bh=pDYhoT s30ht1rC0Yo2i9c88/drzEMyVIy8VmKtI9YQ8=; b=B4FhQfW1LEXUrdvHbVjMZI fteuAZ+IRaI21egOpboRBit3LYRuFw0B9mDwTpKDtSLn2CqOmYz6xFcLsOB3KiUh DVObYO3HvVqOnaM8CyUe0K4nOHnex602NcjFVtVve/GtoHYFYSr6lQ79VC3Zx6Gd FjnPk/IV3SEbdsn4a4rMs0vvJuH4f9WObRAVwREPJoEVcGWRDlthPEd+nzrAaNDZ lzdruz59eRt9GoZ8rxvwvJ+V7vOLvw1m8xUiysF9DOI3s7fhajYszgDLUf5Vy7TB SmVt5CREfX7Wxm7hoCdvA2dVu1m3umXPICILDKV9EmewzpCyxxA7Pq7zc2fQXYoA ==
X-ME-Sender: <xms:1fULYTff8fMS5hrlB0R4pETA0xnHMMB-EAc5wPSZI_DMqhnbRNec9A> <xme:1fULYZOQMe0dZjBWHksVVdO535DKMqRldVdCet9rZ5X-MPplpbvReIT_h7d5OW1wa 2-8sEVeJfOCUFgTkoI>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrieelgdejgecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecunecujfgurhepofgfggfkjghffffhvffutgesthdtre dtreertdenucfhrhhomhepfdevhhhrihhsthhophhhvghrucghohhougdfuceotggrfies hhgvrghpihhnghgsihhtshdrnhgvtheqnecuggftrfgrthhtvghrnhepveekgedtgfdtje fhteeifeejhfdtgfdufedufeeljeeuvdejtdfhvefgvefgvedtnecuffhomhgrihhnpehg ihhthhhusgdrtghomhenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrih hlfhhrohhmpegtrgifsehhvggrphhinhhgsghithhsrdhnvght
X-ME-Proxy: <xmx:1fULYcj44j53WkPmqDNEwq3r2lTsB4ESljlxqR9AmyBrAri8TNCCRg> <xmx:1fULYU8Ja7_wwzFDUuBNie9Dhg0adKPM348rQ42XR3Bx0Zu5OeSgmA> <xmx:1fULYfu0B_7rDQsg46JiBiPEA3UQMNfLVfNpwiGaQnNDB5hhRFXPAg> <xmx:1fULYd5ZFKTE1_PXQNM4P1pFuiQ3FTau6ZNQ5TiVLuy8n0QVJXHCRg>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 7BDDD3C0449; Thu, 5 Aug 2021 10:29:41 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-551-g8030b8c701-fm-20210804.001-g8030b8c7
Mime-Version: 1.0
Message-Id: <e1c47957-53ec-41e2-9911-9f61e5a5425c@www.fastmail.com>
In-Reply-To: <c03b6c39-7100-4ad6-be0c-c00d6cb825c5@www.fastmail.com>
References: <CAMr0u6=9yBqGPf5aKVG0wpFimS-+T8NSHE8QPpXFysaSZb6vMQ@mail.gmail.com> <c03b6c39-7100-4ad6-be0c-c00d6cb825c5@www.fastmail.com>
Date: Thu, 05 Aug 2021 07:29:21 -0700
From: "Christopher Wood" <caw@heapingbits.net>
To: cfrg@irtf.org
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/aALBXSa6iT0A8YN3kccH1eFOQW4>
Subject: Re: [CFRG] HPKE: final call for objections on the changes
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Aug 2021 14:29:48 -0000

On Thu, Aug 5, 2021, at 1:46 AM, Martin Thomson wrote:
> I have read, implemented, and deployed the changes in HPKE since -07.
> 
> I do want to confirm however that the change in test vectors between 
> -08 (where the final version string was added) and -09 was just the 
> result of missing the test vectors in the -08 update.  I've code that 
> uses the source JSON file, which were updated one day after -08 was 
> published.

-08 was not missing test vector updates. The test vector changes in -09 came from renaming some fields in the test vector generation code, and then rerunning that code:

   https://github.com/cfrg/draft-irtf-cfrg-hpke/pull/224

The JSON file in the repository matches those in the latest version of the document. (These have been checked and confirmed by multiple people, though we welcome additional confirmation.)

> Nit: in \S9.7.5, the first sentence could use an em-dash (' - ' or ' -- 
> ' to taste):
>    If the randomness used for KEM encapsulation is bad - i.e., of low	
>    entropy or compromised because of a broken or subverted random 
> number	
>    generator - the confidentiality guarantees of HPKE degrade	
>    significantly.

Done: https://github.com/cfrg/draft-irtf-cfrg-hpke/pull/236

Best,
Chris