Re: [kitten] PA-ENC-TIMESTAMP is worse than we thought; fix in aes-cts-hmac-sha2?

"Henry B (Hank) Hotz, CISSP" <hbhotz@oxy.edu> Tue, 12 April 2016 22:20 UTC

Return-Path: <hbhotz@oxy.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44B6112D6E8 for <kitten@ietfa.amsl.com>; Tue, 12 Apr 2016 15:20:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.39
X-Spam-Level:
X-Spam-Status: No, score=-0.39 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_BL=0.01, RCVD_IN_MSPIKE_L3=2.2] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u_1Xw-JdzKrm for <kitten@ietfa.amsl.com>; Tue, 12 Apr 2016 15:20:39 -0700 (PDT)
Received: from mailout.easymail.ca (mailout.easymail.ca [64.68.201.169]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E44BA12D7F5 for <kitten@ietf.org>; Tue, 12 Apr 2016 15:20:38 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mailout.easymail.ca (Postfix) with ESMTP id 86549EE5D; Tue, 12 Apr 2016 18:20:35 -0400 (EDT)
X-Virus-Scanned: Debian amavisd-new at mailout.easymail.ca
Received: from mailout.easymail.ca ([127.0.0.1]) by localhost (easymail-mailout.easydns.vpn [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VTW8sE+hXILk; Tue, 12 Apr 2016 18:20:34 -0400 (EDT)
Received: from [192.168.1.180] (wsip-174-76-19-88.oc.oc.cox.net [174.76.19.88]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mailout.easymail.ca (Postfix) with ESMTPSA id 1D36DEDA8; Tue, 12 Apr 2016 18:20:32 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2104\))
From: "Henry B (Hank) Hotz, CISSP" <hbhotz@oxy.edu>
In-Reply-To: <20160412214556.GE19617@localhost>
Date: Tue, 12 Apr 2016 15:20:30 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <0429C8B0-96BE-46FB-8434-5AB65B6D82E3@oxy.edu>
References: <20160412214556.GE19617@localhost>
To: Nico Williams <nico@cryptonector.com>
X-Mailer: Apple Mail (2.2104)
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/_fyc9iTAtKW1K_3KTJwtKZbMChE>
Cc: kitten@ietf.org, "Michael J. Jenkins" <mjjenki@tycho.ncsc.mil>, "Kelley W. Burgin" <kelley.burgin@gmail.com>
Subject: Re: [kitten] PA-ENC-TIMESTAMP is worse than we thought; fix in aes-cts-hmac-sha2?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Apr 2016 22:20:41 -0000

> On Apr 12, 2016, at 2:45 PM, Nico Williams <nico@cryptonector.com> wrote:
> 
> That's nice, but... why did we ever have non-randomly-generated salts?
> 
> "Convenience" seems like a nice explanation, but I suspect it wasn't
> just that: it may have been a half-baked security feature.

I guess that’s a valid description. AFAIK time stamps were used because because there was no way to prevent replay attacks if you used the random nonce specified in the original Needham-Schroeder algorithm.

Anyone know when JAAS will support FAST or PKINIT?


Personal: hbhotz@oxy.edu
Business: hhotz@securechannels.com
https://www.linkedin.com/in/hbhotz/