Re: On shared keys (was RE: SOI: identity protection and DOS)
"david chen" <ietf_davidchen@hotmail.com> Thu, 29 November 2001 01:43 UTC
Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id fAT1h9828366; Wed, 28 Nov 2001 17:43:09 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id TAA09802 Wed, 28 Nov 2001 19:50:15 -0500 (EST)
X-Originating-IP: [66.31.70.172]
From: david chen <ietf_davidchen@hotmail.com>
To: "Dilkie, Lee" <Lee_Dilkie@mitel.com>, 'Alex Alten' <Alten@home.com>, andrew.krywaniuk@alcatel.com, 'IPsec WG' <ipsec@lists.tislabs.com>
References: <29B5A21C13C8D51190F900805F65B4EC39EFC8@rndex50.ottawa.mitel.com>
Subject: Re: On shared keys (was RE: SOI: identity protection and DOS)
Date: Wed, 28 Nov 2001 19:59:56 -0500
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-ID: <OE360KrCZpmM4E4Rnpn0000254a@hotmail.com>
X-OriginalArrivalTime: 29 Nov 2001 00:59:17.0538 (UTC) FILETIME=[1237F820:01C17871]
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk
Certificate is great except no one sign the CA's public key. (yes, keeping moving along the 'chain' and reach top) Noone certify the root-CA's public key in a realm. Also, this CA's cert is very valuable for attacker. The self-cert is just a showdow of pre-shared key. (still proving) If the certificate chain ultimately depends on the same mechanism as pre-shared key then just using pre-shared key is sufficient. A raw public key with ID without certificate chain and CA is more simple and efficient. (and no complication of CRL) Only way out of using CA and cert-chain is that Uinted Nation post its public key on major TV network on earth with 24/7 broadcasting and all certifcation of public keys are ultimately based on it. (It will be secure but no civil privacy :-) As far as PGP, it is fuzzy about how secure it is. More like each personal have a relative degree of mutual trust. However, the degree of trust of a group (of people) to a certain person is hard to quantify. (arithmatic average of "trust" in the group, or geometric average of that...) I am lost. :-) --- David ----- Original Message ----- From: "Dilkie, Lee" <Lee_Dilkie@mitel.com> To: "'Alex Alten'" <Alten@home.com>; <andrew.krywaniuk@alcatel.com>; "'IPsec WG'" <ipsec@lists.tislabs.com> Sent: Wednesday, November 28, 2001 5:16 PM Subject: RE: On shared keys (was RE: SOI: identity protection and DOS) > Alex, > > With all due respect, I think the ATM network is a great example of why PSK (symmetric kind) security is an expensive and non scalable solution. > > First of all, the banks do take security seriously and implement the DES security for ATM's the way we suggest for PSK, but no-body does. > > Every ATM is loaded with x months of DES keys by two security guards. Each guard holds one half of a master key that is used to unlock the sets of keys to be loaded into the ATM. You call this a simple and scalable solution? I don't think so. It's expensive as heck, but fortunately for the banks, we get to foot the bill. > > And I disagree that internet hosts are an order of magnitude smaller in deployment. > > Consider the current situation with SSL-based web transactions. If you consider the number of endpoints, both servers and browsers, participating in a trusted, secured transaction I think you'll find that those numbers are vastly larger than the number of ATMs in the world. The certificate-based trust model is far easier and much more managable to deploy than any shared secret scheme. (I'd sure consider it expensive to have two burly security guards show up at my front door to load 4 months of DES keys into my browser) > > Personally, I'd like to see the end of all PSK in IPSec and go to a certificate-based PK trust model. Which is why I really liked the JFK proposal. To those that would like raw public keys, I say this. It's not hard to wrap a PK in a self-signed certificate and it buys you a lot. Moving up to a CA chain buys you that much more. > > And finally, as for the compromises of credit card numbers and the like... Not one of those was due to a flaw in security protocols. They were a result of implementation errors in applications. Unfortunately (or maybe fortunately) IPSec does not take on that responsibility. > > Lee Dilkie > > Mitel Networks > 350 Legget Drive > Kanata, ON, Canada > K2K 2W7 > > Phone: 1-613-592-5660 > > "It wasn't easy to juggle a pregnant wife and a troubled child, but somehow I managed to fit in eight hours of TV a day." > - Homer Simpson (from "The Simpsons") > > > > -----Original Message----- > > From: Alex Alten [mailto:Alten@home.com] > > Sent: Wednesday, November 28, 2001 3:54 PM > > To: andrew.krywaniuk@alcatel.com; 'IPsec WG' > > Subject: RE: On shared keys (was RE: SOI: identity protection and DOS) > > > > > > > > You have completely missed my point, and incorrectly lumped > > Visa and ATM > > security systems together. > > > > My point is that for over 20 years hundred's of millions of > > people have > > been using *DES* to get cash out of ATM machines. This is a > > very large > > scale system, the number of Internet hosts is an order of > > magnitude smaller. > > As far as I know there has never been a major compromise of > > this system, > > where lots of money was stolen from thousands of accounts. > > > > - Alex > > > > > > At 08:58 PM 11/27/2001 -0500, Andrew Krywaniuk wrote: > > >Your argument is silly. > > > > > >Visa and ATM transactions aren't secure. There are multiple > > cases where > > >large credit card databases have been compromised (often > > when an online > > >merchant's website is hacked). > > ... > > > > > > > > >> -----Original Message----- > > >> From: owner-ipsec@lists.tislabs.com > > >> [mailto:owner-ipsec@lists.tislabs.com]On Behalf Of Alex Alten > > >> Sent: Tuesday, November 27, 2001 12:24 PM > > >> To: Hugo Krawczyk; IPsec WG > > >> Subject: Re: On shared keys (was RE: SOI: identity > > protection and DOS) > > >> > > >> > > >> At 01:34 AM 11/27/2001 +0200, Hugo Krawczyk wrote: > > >> >Everyone agrees that public key is the ONLY way to a scalable > > >> >Internet-wide protocol. No question about it. In particular, > > >> >any key-exchange protocol for IPsec MUST provide a > > PK-based exchange. > > >> > > > >> > > >> No. I STRONGLY disagree. I'll give a counter example. > > The banking > > >> ATM network uses DES keys. It has scaled, in practice, world wide. > > >> > > >> And BTW, it's security & trust model is excellent. Have you > > >> ever heard > > >> of a major compromise, say on the scale of 25,000 card #'s > > >> being stolen > > >> (like with Visa?). Certainly nobody distrusts it because it uses > > >> symmetric keys for authentication. In fact I'm certain > > YOU trust it > > >> at least a couple a times a month. :-) > > >> > > > > -- > > > > Alex Alten > > Alten@Home.Com > > >
- I-D ACTION:draft-ietf-ipsec-son-of-ike-protocol-r… Internet-Drafts
- SOI: preshared Michael Thomas
- SOI: identity protection and DOS Michael Thomas
- SOI: round tripiness Michael Thomas
- Re: SOI: preshared Henry Spencer
- Re: SOI: identity protection and DOS Paul Koning
- Re: SOI: identity protection and DOS Joern Sierwald
- Re: SOI: preshared Michael Thomas
- Re: SOI: preshared Henry Spencer
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: preshared Paul Hoffman / VPNC
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: preshared Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Ari Huttunen
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Radia Perlman - Boston Center for Networking
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Arne Ansper
- Re: SOI: identity protection and DOS Sandy Harris
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: preshared Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Ari Huttunen
- Re: SOI: preshared DavidChenNH
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Richard Guy Briggs
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Hugo Krawczyk
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Paul Hoffman / VPNC
- Re: SOI: identity protection and DOS Steven M. Bellovin
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Sara Bitan
- RE: SOI: identity protection and DOS Andrew Krywaniuk
- RE: SOI: identity protection and DOS Paul Hoffman / VPNC
- On shared keys (was RE: SOI: identity protection … Hugo Krawczyk
- Re: SOI: identity protection and DOS Hugo Krawczyk
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: identity protection and DOS Ari Huttunen
- Re: SOI: identity protection and DOS Alex Alten
- On shared keys (was RE: SOI: identity protection … Michael Thomas
- Re: On shared keys (was RE: SOI: identity protect… Alex Alten
- Re: SOI: identity protection and DOS Hugo Krawczyk
- Re: SOI: identity protection and DOS Hugo Krawczyk
- Re: SOI: identity protection and DOS Michael Thomas
- Re: SOI: identity protection and DOS Derek Atkins
- Re: On shared keys Ricky Charlet
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- Re: On shared keys (was RE: SOI: identity protect… Michael Thomas
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Steven M. Bellovin
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: identity protection and DOS Steven M. Bellovin
- RE: On shared keys (was RE: SOI: identity protect… Andrew Krywaniuk
- RE: SOI: identity protection and DOS Andrew Krywaniuk
- Re: SOI: identity protection and DOS Derek Atkins
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Richard Guy Briggs
- Re: SOI: identity protection and DOS Arne Ansper
- Re: Gee, shared secrets suck (was: Re: SOI: ident… David Jablon
- Re: SOI: identity protection and DOS Arne Ansper
- Re: SOI: identity protection and DOS Henry Spencer
- Re: SOI: identity protection and DOS Steven M. Bellovin
- Re: SOI: identity protection and DOS Henry Spencer
- RE: SOI: identity protection and DOS Paul Koning
- Gee, shared secrets suck (was: Re: SOI: identity … Joel Snyder
- Re: Gee, shared secrets suck (was: Re: SOI: ident… david chen
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS david chen
- Re: On shared keys Tylor Allison
- Re: SOI: identity protection and DOS david chen
- Re: SOI: identity protection and DOS Paul Koning
- RE: On shared keys (was RE: SOI: identity protect… Alex Alten
- RE: SOI: identity protection and DOS Andrew Krywaniuk
- RE: SOI: identity protection and DOS Hugo Krawczyk
- Re: SOI: identity protection and DOS david chen
- RE: On shared keys (was RE: SOI: identity protect… Dilkie, Lee
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- Re: On shared keys Jari Arkko
- Re: On shared keys (was RE: SOI: identity protect… Alex Alten
- Re: On shared keys (was RE: SOI: identity protect… david chen
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- Re: On shared keys sami.vaarala
- Re: On shared keys (was RE: SOI: identity protect… Paul Koning
- Re: On shared keys Derek Atkins
- Re: On shared keys Henry Spencer
- Re: Gee, shared secrets suck (was: Re: SOI: ident… Arne Ansper
- Re: On shared keys Derek Atkins
- Re: On shared keys Arne Ansper
- RE: On shared keys Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… Stephen Kent
- Re: On shared keys Sami Vaarala
- Re: On shared keys Sami Vaarala
- RE: On shared keys (was RE: SOI: identity protect… Alex Alten
- Re: On shared keys Derek Atkins
- Re: On shared keys Sami Vaarala
- Re: On shared keys (was RE: SOI: identity protect… Sandy Harris
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: On shared keys (was RE: SOI: identity protect… Khaja E. Ahmed
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… Derek Atkins
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- Re: On shared keys (was RE: SOI: identity protect… Sandy Harris
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: SOI: identity protection and DOS Andrew Krywaniuk
- RE: On shared keys (was RE: SOI: identity protect… Wang, Cliff
- Re: On shared keys (was RE: SOI: identity protect… david chen
- RE: SOI: identity protection and DOS Hugo Krawczyk
- SA look up Jin Zhang
- RE: SA look up Li, Ruicong