Re: [jose] Secdir review of draft-ietf-jose-json-web-signature-31
Tero Kivinen <kivinen@iki.fi> Mon, 22 September 2014 13:27 UTC
Return-Path: <kivinen@iki.fi>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D183E1A1ADB; Mon, 22 Sep 2014 06:27:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.786, SPF_NEUTRAL=0.779] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eZKYPKo6JQKW; Mon, 22 Sep 2014 06:27:06 -0700 (PDT)
Received: from mail.kivinen.iki.fi (fireball.kivinen.iki.fi [IPv6:2001:1bc8:100d::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A56071A1AC9; Mon, 22 Sep 2014 06:27:03 -0700 (PDT)
Received: from fireball.kivinen.iki.fi (localhost [127.0.0.1]) by mail.kivinen.iki.fi (8.14.8/8.14.8) with ESMTP id s8MDQwTr026343 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 22 Sep 2014 16:26:58 +0300 (EEST)
Received: (from kivinen@localhost) by fireball.kivinen.iki.fi (8.14.8/8.14.8/Submit) id s8MDQun3023591; Mon, 22 Sep 2014 16:26:56 +0300 (EEST)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <21536.9120.451498.905934@fireball.kivinen.iki.fi>
Date: Mon, 22 Sep 2014 16:26:56 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: Richard Barnes <rlb@ipv.sx>
In-Reply-To: <CAL02cgQfCRzUjrKLbyyNTFoKGxKrUnOqH1n6WS-SciWeBrgJzQ@mail.gmail.com>
References: <21512.21725.209461.976375@fireball.kivinen.iki.fi> <4E1F6AAD24975D4BA5B16804296739439AE9DD47@TK5EX14MBXC292.redmond.corp.microsoft.com> <CAL02cgSsi603XL2o4S89pAw64yLv0JRZaDg823uiyuTkm02AHA@mail.gmail.com> <21527.63989.999440.801542@fireball.kivinen.iki.fi> <CAL02cgQKfQr_dQ=0-oY19G4rmYL3928UWFLBfhDAyspwMU7W9g@mail.gmail.com> <21529.16232.880915.215045@fireball.kivinen.iki.fi> <CAL02cgSRmP+iRYqTPUdcgTipeDw1H8TdF3AMP-ORSqOwiWJEcQ@mail.gmail.com> <4E1F6AAD24975D4BA5B16804296739439BA59EB7@TK5EX14MBXC286.redmond.corp.microsoft.com> <CAL02cgRTmsVTkwwDMbHtcqHzCs6GkOz-uZ_SOKNeR3hxJZMdDw@mail.gmail.com> <03a601cfd460$f8d71d70$ea855850$@augustcellars.com> <C9BA46F1-5F30-47C7-A90A-689C5DA084F6@ve7jtb.com> <03c701cfd483$d1cf45e0$756dd1a0$@augustcellars.com> <F70DA0F7-A855-49A8-A514-39AB8862AF74@ve7jtb.com> <043a01cfd4f2$3df75ff0$b9e61fd0$@augustcellars.com> <457A8BF9-8CDF-43C8-8040-CB42BE110805@ve7jtb.com> <CAL02cgQfCRzUjrKLbyyNTFoKGxKrUnOqH1n6WS-SciWeBrgJzQ@mail.gmail.com>
X-Mailer: VM 8.2.0b under 24.3.1 (x86_64--netbsd)
X-Edit-Time: 15 min
X-Total-Time: 19 min
Archived-At: http://mailarchive.ietf.org/arch/msg/jose/McBrjM-xvm-1y6Hwk6MxnceXXYg
X-Mailman-Approved-At: Mon, 22 Sep 2014 06:45:03 -0700
Cc: "ietf@ietf.org" <ietf@ietf.org>, secdir <secdir@ietf.org>, Jim Schaad <ietf@augustcellars.com>, Michael Jones <Michael.Jones@microsoft.com>, IESG <iesg@ietf.org>, "jose@ietf.org" <jose@ietf.org>, John Bradley <ve7jtb@ve7jtb.com>, "draft-ietf-jose-json-web-signature.all@tools.ietf.org" <draft-ietf-jose-json-web-signature.all@tools.ietf.org>
Subject: Re: [jose] Secdir review of draft-ietf-jose-json-web-signature-31
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Sep 2014 13:27:18 -0000
Richard Barnes writes: > * Given an existing signature, an attacker can find another payload > that produces the same signature value with a weaker algorithm I think one of the major points is that hash algorithms try to make sure that collisions are hard but ONLY INSIDE the same algorithm. I.e. it is hard to find collisions for SHA-256. On the other hand nothing is said how hard it is said to create SHA-1 hash that matches some SHA-256-160 message. I.e. all the security analysis we have for SHA-256 are worthless as they do not cover creating collision between SHA-256 and SHA-1. I.e. SHA-256 was designed to be collision resistant with SHA-256, but not with SHA-1. It might be secure, or it might not. I think there are some papers talking about creating collisions between MD5 and SHA-1, but those are done by analysing the hash functions, i.e. not while designing the algorithms. I.e. this kind of attacks were not major design criteria when algorithms were made. I.e. most of the properties designed in to the hash functions are not true anymore if we try to match two different algorithms against each other. On the other hand I think that one of the design criteria for creating SHA-2 family was that there is no collisions between different algorithms in the same family. -- kivinen@iki.fi
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Jim Schaad
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Jim Schaad
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… Jim Schaad
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… John Bradley
- Re: [jose] Secdir review of draft-ietf-jose-json-… Jim Schaad
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Jim Schaad
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Richard Barnes
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Tero Kivinen
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones
- Re: [jose] Secdir review of draft-ietf-jose-json-… Mike Jones