Re: [jose] W3C project proposal using stacked signatures

Anders Rundgren <anders.rundgren.net@gmail.com> Thu, 26 November 2015 20:27 UTC

Return-Path: <anders.rundgren.net@gmail.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E1D4D1B2E53 for <jose@ietfa.amsl.com>; Thu, 26 Nov 2015 12:27:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tALB4xHNKF4O for <jose@ietfa.amsl.com>; Thu, 26 Nov 2015 12:27:54 -0800 (PST)
Received: from mail-wm0-x22a.google.com (mail-wm0-x22a.google.com [IPv6:2a00:1450:400c:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A8BC1B2E52 for <jose@ietf.org>; Thu, 26 Nov 2015 12:27:54 -0800 (PST)
Received: by wmec201 with SMTP id c201so35018668wme.1 for <jose@ietf.org>; Thu, 26 Nov 2015 12:27:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-type:content-transfer-encoding; bh=3H8zWxV9RXrQeU99wPshZw8cQyem6nWMFOn4swdX56g=; b=VXPxEWaA3kRU/swe46vgHqid2w86XqR0yTn9AV7FsUy4R+rDw7w+eQ1Dbo7UB7PVHW j6tKxbvjAXyahaf9Ths2LBCHw6uuUIFa76/jKz25lHvW3dvr1TUnj4Fq7HP5Y9wYqxre 6kTo3CwuNlSZVYiGzdRnK0j0tWBJsbZUiFm8EJY/OVBeKZArXzjUTwjUuw9/jIQs9P79 uCAnUcVXigYrrAXgXuQnKDJzNB1yGvNKt1qbgLUQuBVPKPMcWM6KfCKa4TDeEYTtVLBD evzqljfw+G16ZGPrF65ZDJ19Ye+jSZLffbi6wEwEwVL4tCWQuY7RttG4o42+mMMvn7tr V8Lg==
X-Received: by 10.28.49.65 with SMTP id x62mr6059795wmx.49.1448569672796; Thu, 26 Nov 2015 12:27:52 -0800 (PST)
Received: from [192.168.1.79] (16.200.130.77.rev.sfr.net. [77.130.200.16]) by smtp.googlemail.com with ESMTPSA id n127sm4279009wmf.12.2015.11.26.12.27.51 (version=TLSv1/SSLv3 cipher=OTHER); Thu, 26 Nov 2015 12:27:52 -0800 (PST)
To: Melinda Shore <melinda.shore@gmail.com>, jose@ietf.org
References: <56573A36.4030006@gmail.com> <56575279.3070807@gmail.com>
From: Anders Rundgren <anders.rundgren.net@gmail.com>
Message-ID: <56576B46.8070900@gmail.com>
Date: Thu, 26 Nov 2015 21:27:50 +0100
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <56575279.3070807@gmail.com>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/jose/K0kyaw0PT-fb1WEHaIYEGW6OoyM>
Subject: Re: [jose] W3C project proposal using stacked signatures
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Nov 2015 20:27:56 -0000

On 2015-11-26 19:42, Melinda Shore wrote:
> On 11/26/15 7:58 AM, Anders Rundgren wrote:
>> Disclaimer: I have not been involved in this in any way...
>> https://www.w3.org/Payments/IG/wiki/Main_Page/ProposalsQ42015/SCAI
>
> FWIW this was in the Payments Interest Group and not the
> Payments Working Group, and it's not clear to me that
> they're actually going to do anything with this.  I would
> double-check with them about what's going on with that.

You are absolutely correct, this is one of huge bunch of proposals:
https://lists.w3.org/Archives/Public/public-webpayments-ig/2015Nov/0074.html

> I agree with you about the proposal being unattractive.

The intention with my message was rather highlighting the mismatch between JOSE
and schemes like the one proposed which (IMO) motivates a renewed JOSE activity
along the lines I have previously described.

After the recent revelations about ES6 and its implementation in some very popular
platforms this seems to be even more useful than I originally thought.  None of
that information and use-cases were at hand when JOSE started.

Anders

>
> Melinda
>
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose
>