Re: [Cfrg] Query about ECDAA security

Peter Gutmann <pgut001@cs.auckland.ac.nz> Sat, 25 August 2018 05:00 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FB06130DC1 for <cfrg@ietfa.amsl.com>; Fri, 24 Aug 2018 22:00:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e8uofW318dFN for <cfrg@ietfa.amsl.com>; Fri, 24 Aug 2018 22:00:45 -0700 (PDT)
Received: from mx4-int.auckland.ac.nz (mx4-int.auckland.ac.nz [130.216.125.246]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 707F21277D2 for <cfrg@irtf.org>; Fri, 24 Aug 2018 22:00:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1535173244; x=1566709244; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=ZXSIcwpp/94qVBM97RcN7LnFWEF5Z2rPqlH503j7lMU=; b=rB1cJrUb1f8hiL7oGdDvD9rxHmy2d9xwGWdzN0x1MXMII0m7IcUZUmor +WH4j/IC/RRIkm9FSRMx5yNGvs+Q6a+h2tVS78LwZB02CRzVltfdr7Nfa e4mCXApKwvz95JoiGvkSXO+ib6IicCD10EuLafhbPmfV9pd3DTNW3hOAw L6tTNgsjcB92qTppFuG+1yck5r3d7fgLRZ4iuq6cqQwwLl1kIdLjwy3nf fS5y4mp8oH/aRqy7EmzixlEYTpPrH6qWc5DZdhkH+ztbmP49aQzBsfBau SCMIAY9GfWtQ4Pt0gdwmgdJlFo2N/A8Xph/wtHnQoh94ihf7Yu2CTDFmq A==;
X-IronPort-AV: E=Sophos;i="5.53,285,1531742400"; d="scan'208";a="27973427"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 10.6.2.8 - Outgoing - Outgoing
Received: from uxcn13-ogg-e.uoa.auckland.ac.nz ([10.6.2.8]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 25 Aug 2018 17:00:40 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz (10.6.2.5) by uxcn13-ogg-e.UoA.auckland.ac.nz (10.6.2.8) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Sat, 25 Aug 2018 17:00:40 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.25]) by uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.5]) with mapi id 15.00.1263.000; Sat, 25 Aug 2018 17:00:39 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Scott Arciszewski <scott@paragonie.com>
CC: "blueroofmusic@gmail.com" <blueroofmusic@gmail.com>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [Cfrg] Query about ECDAA security
Thread-Index: AQHUOxGwep2Pgl+qb0KuRu1lLKAT0KTOrXNn//9rZwCAAdHoWw==
Date: Sat, 25 Aug 2018 05:00:39 +0000
Message-ID: <1535173231523.90728@cs.auckland.ac.nz>
References: <CAN40gSv47ai1uXmyKf7EWn2Jp-pwPGhH63u=dGMgXicf4gwOAQ@mail.gmail.com> <1535105288152.75254@cs.auckland.ac.nz>, <CAKws9z1i9c0iDQuHM3z7D3xqNsGxa4uHRWpmoftDxg+H79tmig@mail.gmail.com>
In-Reply-To: <CAKws9z1i9c0iDQuHM3z7D3xqNsGxa4uHRWpmoftDxg+H79tmig@mail.gmail.com>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/dOevnVP0UC0DG5Wbaxk9Dafavlw>
Subject: Re: [Cfrg] Query about ECDAA security
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Aug 2018 05:00:48 -0000

Scott Arciszewski <scott@paragonie.com> writes:

>As frustrating as it is, unless we produce standards that are easy for non-
>cryptography folks to use securely in their software (and, even better,
>difficult to use insecurely), we will encounter insecure implementations in
>the wild.

Absolutely.

There's another problem though, in that a lot of the more secure mechanisms
are both really, really complex (compare just the basic OAEP vs. PKCS#1 v1.5)
and often have very little mainstream library support, or if support is
present it's little-tested and little-evaluated because of it's non-mainstream
nature.  As a result, developers have the choice of (say) RSA-PKCSv1.5 and
hoping the library gets it right, or RSA-PSS, possibly having to roll it
themselves, and being non-interoperable with most of the planet when the get
it implemented.

That's another issue with point compression that follows on from the patent
issues, standards like TLS have allowed point compression since forever (the
ec_point_formats extension is mandatory for TLS with ECC), but the spec says:

  Implementations of this document MUST support the uncompressed format for
  all of their supported curves and MUST NOT support other formats for curves
  defined in this specification.

  If the client sends the extension and the extension does not contain the
  uncompressed point format, and the client has used the Supported Groups
  extension to indicate support for any of the curves defined in this
  specification, then the server MUST abort the handshake and return an
  illegal_parameter alert.

The same thing is reflected in other standards, and in crypto libraries.  So
you often have to make a choice between "less than perfect theoretically but
universally deployed" and "(allegedly) perfect theoretically but you'll be in
for a shock when you try and deploy it".

Peter.