Re: [kitten] Comments on draft-ietf-kitten-password-storage-02

Sam Whited <sam@samwhited.com> Mon, 23 November 2020 12:28 UTC

Return-Path: <sam@samwhited.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 079CE3A09EC for <kitten@ietfa.amsl.com>; Mon, 23 Nov 2020 04:28:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.22
X-Spam-Level:
X-Spam-Status: No, score=-0.22 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=samwhited.com header.b=pqJKgWOB; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=hRK5NxlF
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jl4mzpLRPx8p for <kitten@ietfa.amsl.com>; Mon, 23 Nov 2020 04:28:14 -0800 (PST)
Received: from wout2-smtp.messagingengine.com (wout2-smtp.messagingengine.com [64.147.123.25]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2C88D3A09EA for <kitten@ietf.org>; Mon, 23 Nov 2020 04:28:14 -0800 (PST)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id 7303F10C0 for <kitten@ietf.org>; Mon, 23 Nov 2020 07:28:13 -0500 (EST)
Received: from imap34 ([10.202.2.84]) by compute4.internal (MEProxy); Mon, 23 Nov 2020 07:28:13 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samwhited.com; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm1; bh=K4rAL krcGo+A/PEGYkXyAYk1hRRvTX/gZd94LzZHHz8=; b=pqJKgWOByNFAN5u2H97Pr jD8fb5NvN/X/O12FRk8KpDxhIh1SnzOX6iGOuuHmFASpvHxeotKV41Neujg2YKjP /u4ldgNmAjnc9nrjyfGkxgNS1aGNhoCn8gEfkjH1cC2HYrKliAf85TQcXiXwvuJu Y7AJZS4p2Idg5BoyvbMEPNYuocklyNh5b0sb6d2qsNDkZdk+QLIeeGtVkTgLaTtW 3qm+T5gaEhumILjjEO4JRqpwvQphhukOs9frZ8YkTwLZMwR6EqmyxZyyODtPwZ7A 4dl+F8Jy9cUkAsIDU6kBcROBuP1K/YRYqRKLfTGmTJ7r9pmMY2+csN9F/GYLeoow w==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; bh=K4rALkrcGo+A/PEGYkXyAYk1hRRvTX/gZd94LzZHH z8=; b=hRK5NxlFYwgS1NnHgr1sV2kXHLH2ajJSG+zeUpDiOT2iWeoZLlONfF4pd O7ndYTAnq469pjsmCo9Sgqd6XNci0AaB+g84Kn0sSFyHn2fwHQyFlblEep9egkrp sqB4WTd7ru0XimRVpLZOR/ePVlIgi6ukNHL4RMHg9tIomgc6u+01KIiX69LPHrWE qBVoJwv/hL31ie0ZwqQ0ZF7TJBgkvP7bqncSqt9hHbguLE22eX162P2Xhx29cxEa eRwknGmgzJLVXRV3sO/uC4sktt8gwK3S6dVxVQxjDZCgHvkJ0kgxugs27R8pvgns fHitKoJAgI4OYK3jy3tbw+e6T+9Mw==
X-ME-Sender: <xms:3Kq7X4B5GAOTG_p81c4u4faxdp3EY5rnb0PXmcq3u_dSvwOjcHKe3w> <xme:3Kq7X6jXipgAcIJNVkieTiYrXZ-9dLeP83RK3pW-AoMV0xGzVxEzIWELIKYwqnUSV H_VKZqgb_L7w7zAkQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedujedrudegiedggeduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvffutgfgsehtqhertderreejnecuhfhrohhmpedfufgr mhcuhghhihhtvggufdcuoehsrghmsehsrghmfihhihhtvggurdgtohhmqeenucggtffrrg htthgvrhhnpedvffeuvdduhfefvdeiheeukeffhfekjeevgffggedtlefhhffhieevkedu vefhjeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpe hsrghmsehsrghmfihhihhtvggurdgtohhm
X-ME-Proxy: <xmx:3Kq7X7kaHyfdZJ4vtXg-Y8Z7oiOVaH0h69j2U7jJCjAGQUHP8Aw_6g> <xmx:3Kq7X-wCsO-kMOqJqRDgXHnA80n9AP6mq_RgrLsaExqa9FhX9UorsA> <xmx:3Kq7X9QKZcY1HNcgXZRXENN-wJErC8X6dqTHQH6LNZuyHtM27bG41Q> <xmx:3aq7X0eUbjW5lKkrgzXrsYgvbqAzDcfI3zn2LZAi7GII6eriC2TuTQ>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id B463A1460062; Mon, 23 Nov 2020 07:28:12 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.3.0-622-g4a97c0b-fm-20201115.001-g4a97c0b3
Mime-Version: 1.0
Message-Id: <ef54dd11-37e8-4e2a-95fc-d70a83d7ec82@www.fastmail.com>
In-Reply-To: <383104680.145048.1606106813679@email.ionos.com>
References: <383104680.145048.1606106813679@email.ionos.com>
Date: Mon, 23 Nov 2020 12:27:52 +0000
From: Sam Whited <sam@samwhited.com>
To: KITTEN Working Group <kitten@ietf.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ZuMiil5rBquMJJPYPqYCNgANsOM>
Subject: Re: [kitten] Comments on draft-ietf-kitten-password-storage-02
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Nov 2020 12:28:16 -0000

On Mon, Nov 23, 2020, at 04:46, steve@tobtu.com wrote:
> scrypt's "output length (dkLen)" of "hLen (length of the chosen hash)"
> is the same wording as PBKDF2, but you can't choose a hash.

Fixed in the next draft, thank you.

> Also same applies to Argon2.

This doesn't appear to be the case for argon2 where I don't list a
length (if I recall correctly the output length isn't one of the argon2
inputs). Is there specific language you think needs to be changed for
the argon2 recommendations? Thanks.

—Sam