Re: [dane] [openpgp] The DANE draft

Hosnieh Rafiee <hosnieh.rafiee@huawei.com> Thu, 06 August 2015 16:01 UTC

Return-Path: <hosnieh.rafiee@huawei.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D0F11B3096 for <dane@ietfa.amsl.com>; Thu, 6 Aug 2015 09:01:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lL6l3P9wni9O for <dane@ietfa.amsl.com>; Thu, 6 Aug 2015 09:01:39 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1A001B3095 for <dane@ietf.org>; Thu, 6 Aug 2015 09:01:38 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml402-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BZO81378; Thu, 06 Aug 2015 16:01:37 +0000 (GMT)
Received: from LHREML504-MBS.china.huawei.com ([10.125.30.107]) by lhreml402-hub.china.huawei.com ([10.201.5.241]) with mapi id 14.03.0235.001; Thu, 6 Aug 2015 17:01:32 +0100
From: Hosnieh Rafiee <hosnieh.rafiee@huawei.com>
To: "dane@ietf.org" <dane@ietf.org>
Thread-Topic: [dane] [openpgp] The DANE draft
Thread-Index: AQHQz1cAG6iEyei+P0uLgSQSGhtjSZ39ND4AgAA+fgCAAAazAIABGZUAgAAVT5P///M3AIAAc2QAgAATJGA=
Date: Thu, 06 Aug 2015 16:01:31 +0000
Message-ID: <814D0BFB77D95844A01CA29B44CBF8A7015D69D2@lhreml504-mbs>
References: <87bnf1hair.fsf@alice.fifthhorseman.net> <alpine.LFD.2.11.1507250832510.854@bofh.nohats.ca> <87bnem2xjq.fsf@alice.fifthhorseman.net> <alpine.LFD.2.11.1508050331340.1451@bofh.nohats.ca> <55C1F35A.5070904@cs.tcd.ie> <B7419740-25C9-4F8D-85AE-FC6E11BCC038@vpnc.org> <55C22D64.9080507@strotmann.de> <alpine.LFD.2.11.1508060417450.16408@bofh.nohats.ca> <20150806163914546863148@cnnic.cn> <alpine.LFD.2.11.1508060447180.16408@bofh.nohats.ca> <20150806154724.GG9139@mournblade.imrryr.org>
In-Reply-To: <20150806154724.GG9139@mournblade.imrryr.org>
Accept-Language: en-US, zh-CN
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.221.97.232]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/3vwLVOzZpNRYcgPIPsmRe5XKOFo>
Subject: Re: [dane] [openpgp] The DANE draft
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Aug 2015 16:01:43 -0000

Viktor,

> -----Original Message-----
> From: dane [mailto:dane-bounces@ietf.org] On Behalf Of Viktor Dukhovni
> Sent: Thursday, August 06, 2015 5:47 PM
> To: dane@ietf.org
> Subject: Re: [dane] [openpgp] The DANE draft
> 
> On Thu, Aug 06, 2015 at 04:54:24AM -0400, Paul Wouters wrote:
> 
> > I really do believe that the hashing is not an affective security
> > meassure.
> 
> Agreed.  Wishful thinking does not make it true.  Just because we'd
> like to sprinkle crypto pixie dust to make magic happen, does not mean
> it will happen.
> 
> Hashes may sound more secure, but they're not really more secure, no
> matter how much we'd like them to be.

Of course, no one expects to see a miracle from a hash function. But again this is only making it a bit harder, even you say 1% but this is quite different than a plain text.

Best,
Hosnieh