Re: [Cfrg] Query about ECDAA security
Peter Gutmann <pgut001@cs.auckland.ac.nz> Sat, 25 August 2018 05:00 UTC
Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FB06130DC1 for <cfrg@ietfa.amsl.com>; Fri, 24 Aug 2018 22:00:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e8uofW318dFN for <cfrg@ietfa.amsl.com>; Fri, 24 Aug 2018 22:00:45 -0700 (PDT)
Received: from mx4-int.auckland.ac.nz (mx4-int.auckland.ac.nz [130.216.125.246]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 707F21277D2 for <cfrg@irtf.org>; Fri, 24 Aug 2018 22:00:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1535173244; x=1566709244; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=ZXSIcwpp/94qVBM97RcN7LnFWEF5Z2rPqlH503j7lMU=; b=rB1cJrUb1f8hiL7oGdDvD9rxHmy2d9xwGWdzN0x1MXMII0m7IcUZUmor +WH4j/IC/RRIkm9FSRMx5yNGvs+Q6a+h2tVS78LwZB02CRzVltfdr7Nfa e4mCXApKwvz95JoiGvkSXO+ib6IicCD10EuLafhbPmfV9pd3DTNW3hOAw L6tTNgsjcB92qTppFuG+1yck5r3d7fgLRZ4iuq6cqQwwLl1kIdLjwy3nf fS5y4mp8oH/aRqy7EmzixlEYTpPrH6qWc5DZdhkH+ztbmP49aQzBsfBau SCMIAY9GfWtQ4Pt0gdwmgdJlFo2N/A8Xph/wtHnQoh94ihf7Yu2CTDFmq A==;
X-IronPort-AV: E=Sophos;i="5.53,285,1531742400"; d="scan'208";a="27973427"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 10.6.2.8 - Outgoing - Outgoing
Received: from uxcn13-ogg-e.uoa.auckland.ac.nz ([10.6.2.8]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 25 Aug 2018 17:00:40 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz (10.6.2.5) by uxcn13-ogg-e.UoA.auckland.ac.nz (10.6.2.8) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Sat, 25 Aug 2018 17:00:40 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.25]) by uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.5]) with mapi id 15.00.1263.000; Sat, 25 Aug 2018 17:00:39 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Scott Arciszewski <scott@paragonie.com>
CC: "blueroofmusic@gmail.com" <blueroofmusic@gmail.com>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [Cfrg] Query about ECDAA security
Thread-Index: AQHUOxGwep2Pgl+qb0KuRu1lLKAT0KTOrXNn//9rZwCAAdHoWw==
Date: Sat, 25 Aug 2018 05:00:39 +0000
Message-ID: <1535173231523.90728@cs.auckland.ac.nz>
References: <CAN40gSv47ai1uXmyKf7EWn2Jp-pwPGhH63u=dGMgXicf4gwOAQ@mail.gmail.com> <1535105288152.75254@cs.auckland.ac.nz>, <CAKws9z1i9c0iDQuHM3z7D3xqNsGxa4uHRWpmoftDxg+H79tmig@mail.gmail.com>
In-Reply-To: <CAKws9z1i9c0iDQuHM3z7D3xqNsGxa4uHRWpmoftDxg+H79tmig@mail.gmail.com>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/dOevnVP0UC0DG5Wbaxk9Dafavlw>
Subject: Re: [Cfrg] Query about ECDAA security
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Aug 2018 05:00:48 -0000
Scott Arciszewski <scott@paragonie.com> writes: >As frustrating as it is, unless we produce standards that are easy for non- >cryptography folks to use securely in their software (and, even better, >difficult to use insecurely), we will encounter insecure implementations in >the wild. Absolutely. There's another problem though, in that a lot of the more secure mechanisms are both really, really complex (compare just the basic OAEP vs. PKCS#1 v1.5) and often have very little mainstream library support, or if support is present it's little-tested and little-evaluated because of it's non-mainstream nature. As a result, developers have the choice of (say) RSA-PKCSv1.5 and hoping the library gets it right, or RSA-PSS, possibly having to roll it themselves, and being non-interoperable with most of the planet when the get it implemented. That's another issue with point compression that follows on from the patent issues, standards like TLS have allowed point compression since forever (the ec_point_formats extension is mandatory for TLS with ECC), but the spec says: Implementations of this document MUST support the uncompressed format for all of their supported curves and MUST NOT support other formats for curves defined in this specification. If the client sends the extension and the extension does not contain the uncompressed point format, and the client has used the Supported Groups extension to indicate support for any of the curves defined in this specification, then the server MUST abort the handshake and return an illegal_parameter alert. The same thing is reflected in other standards, and in crypto libraries. So you often have to make a choice between "less than perfect theoretically but universally deployed" and "(allegedly) perfect theoretically but you'll be in for a shock when you try and deploy it". Peter.
- [Cfrg] Query about ECDAA security Ira McDonald
- Re: [Cfrg] Query about ECDAA security Jim Schaad
- Re: [Cfrg] Query about ECDAA security Peter Gutmann
- Re: [Cfrg] Query about ECDAA security Scott Arciszewski
- Re: [Cfrg] Query about ECDAA security Dan Brown
- Re: [Cfrg] Query about ECDAA security Peter Gutmann
- Re: [Cfrg] Query about ECDAA security Dan Brown
- Re: [Cfrg] Query about ECDAA security Tony Arcieri
- Re: [Cfrg] Query about ECDAA security Shoko YONEZAWA