Re: [dsfjdssdfsd] Any plans for drafts or discussions on here?

"Dan Harkins" <dharkins@lounge.org> Wed, 22 January 2014 20:29 UTC

Return-Path: <dharkins@lounge.org>
X-Original-To: dsfjdssdfsd@ietfa.amsl.com
Delivered-To: dsfjdssdfsd@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 25D8D1A0490 for <dsfjdssdfsd@ietfa.amsl.com>; Wed, 22 Jan 2014 12:29:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.867
X-Spam-Level:
X-Spam-Status: No, score=-3.867 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pwl6r7gSbcfp for <dsfjdssdfsd@ietfa.amsl.com>; Wed, 22 Jan 2014 12:29:06 -0800 (PST)
Received: from colo.trepanning.net (colo.trepanning.net [69.55.226.174]) by ietfa.amsl.com (Postfix) with ESMTP id A18751A0493 for <dsfjdssdfsd@ietf.org>; Wed, 22 Jan 2014 12:29:04 -0800 (PST)
Received: from www.trepanning.net (localhost [127.0.0.1]) by colo.trepanning.net (Postfix) with ESMTP id D0C8810224008; Wed, 22 Jan 2014 12:29:03 -0800 (PST)
Received: from 205.201.168.123 (SquirrelMail authenticated user dharkins@lounge.org) by www.trepanning.net with HTTP; Wed, 22 Jan 2014 12:29:04 -0800 (PST)
Message-ID: <ebd5a19a1b00035e1493f019b5ca09e7.squirrel@www.trepanning.net>
In-Reply-To: <7F55125F-1669-4A36-A4A5-C1655CDCE77A@vpnc.org>
References: <52DD996F.3040708@cs.tcd.ie> <CAF4+nEHEWaSr3HMuGtQ=vQzuuhkTo2uNpedUTNgmT5NsWRsTfA@mail.gmail.com> <30316745-8091-46AD-95A1-407757489FF9@vpnc.org> <e309a1b8c4a77ce1da4adfab1fc1db37.squirrel@www.trepanning.net> <F6B381C1-089D-4723-9A2C-7937C6C74EFB@vpnc.org> <eaa6cc3f162888d40834d61907256a26.squirrel@www.trepanning.net> <7F55125F-1669-4A36-A4A5-C1655CDCE77A@vpnc.org>
Date: Wed, 22 Jan 2014 12:29:04 -0800 (PST)
From: "Dan Harkins" <dharkins@lounge.org>
To: "Paul Hoffman" <paul.hoffman@vpnc.org>
User-Agent: SquirrelMail/1.4.14 [SVN]
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-1
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
Cc: dsfjdssdfsd@ietf.org
Subject: Re: [dsfjdssdfsd] Any plans for drafts or discussions on here?
X-BeenThere: dsfjdssdfsd@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The dsfjdssdfsd list provides a venue for discussion of randomness in IETF protocols, for example related to updating RFC 4086." <dsfjdssdfsd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dsfjdssdfsd>, <mailto:dsfjdssdfsd-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dsfjdssdfsd/>
List-Post: <mailto:dsfjdssdfsd@ietf.org>
List-Help: <mailto:dsfjdssdfsd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dsfjdssdfsd>, <mailto:dsfjdssdfsd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jan 2014 20:29:08 -0000

On Wed, January 22, 2014 11:16 am, Paul Hoffman wrote:
> On Jan 22, 2014, at 10:40 AM, Dan Harkins <dharkins@lounge.org> wrote:
>
>>  To minimize the possibility of someone borking their DRBG
>> implementation
>> we can include some test vectors-- instantiating with A produces state
>> of
>> B; reseeding of state B with C produces state D; generating with state D
>> produces E, etc.
>
> If we could be sure that there was no way for the mechanisms needed to
> test those vectors could possibly appear in an implementation, that would
> be great. If we can't be sure of that, we are proposing an implementer
> include something that could cause a catastrophic failure if those inputs
> are accidentally left in.

  That seems like an absurdly high bar-- that there is no way someone
could so something demonstrably stupid. We use test vectors when
specifying things like HKDF or AES-<pick your mode> and no one
seems to generate a function that only accepts those inputs and only
produces the specified outputs. I really don't think people will suddenly
start  hard-coding test vectors into code now.

> Regardless, that's not what Don's draft does.

  I'm still hoping that an Informational RFC on a good DRBG will be
generated.

>>  The more people that implement anything will increase the probability
>> of
>> a broken implementation somewhere, I definitely agree. But it is an
>> accepted
>> economic truth that relying on a single source for anything is a bad
>> idea.
>
> That seems like a strawman: who says that there is a "single source" of
> ideas for how to implement randomness? Three large server OSs (Linux,
> FreeBSD, Windows) all do it differently.

  The single source is "your OS". While there are 3 large server OSs, there
is no single application that can obtain randomness from all three since
there is no application that runs on all of them (and my experience is
that a single linux application won't necessarily work from version X of
the OS to version Y-- hell, sometimes the source won't even compile).

  And you know, the "if we could be sure there was no way…" thing works
both ways, especially regarding a large (monopoly) OS whose track
record on security and code quality is not perfect.

  Dan.