Re: [kitten] Comments on draft-ietf-kitten-password-storage-03

Sam Whited <sam@samwhited.com> Fri, 12 March 2021 19:12 UTC

Return-Path: <sam@samwhited.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 442673A1A6D for <kitten@ietfa.amsl.com>; Fri, 12 Mar 2021 11:12:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.82
X-Spam-Level:
X-Spam-Status: No, score=-2.82 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=samwhited.com header.b=Jig45+5k; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=MxKJYFzd
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UWnfGZBOCH2X for <kitten@ietfa.amsl.com>; Fri, 12 Mar 2021 11:12:00 -0800 (PST)
Received: from wout3-smtp.messagingengine.com (wout3-smtp.messagingengine.com [64.147.123.19]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C51953A193D for <kitten@ietf.org>; Fri, 12 Mar 2021 11:12:00 -0800 (PST)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id AC0B71813 for <kitten@ietf.org>; Fri, 12 Mar 2021 14:11:59 -0500 (EST)
Received: from imap34 ([10.202.2.84]) by compute4.internal (MEProxy); Fri, 12 Mar 2021 14:11:59 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samwhited.com; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm2; bh=Q5gAN jFOuKYIzy3c67U6tIpPkFK/VjCuaBtrjOVPv/0=; b=Jig45+5kgDAD8VuHb2y55 Tz4GnGJdyUIhl+4xMg2jY1UQkqNDP0zsKzHNMzyK/XL7n0zzstRgMJJm+9goCdIy TLVXrR9tWL4rsXE9ykOdjvk8NC/p9J3VlXReyMHXASeRVCTN5zgAkDlR/OZ8sabT z6Ke5ooT6lcd12CAra1ya35Yg8eMQ2G+QPQ4KcSNVRM48km0lVFJGw/XG8RfcMf2 suHt8+4GrNLU8QtKCq5wys/00MaHa0K/9T+JT1C1HDF+aLZ1Qeygg3qUSMC6A74y 9j+r9O2SC3D8uh3pF9OdI22JhN9B1n16/XdZfJNWkwBz+pmZhwrgwqgF/HvfqkcJ w==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=Q5gANjFOuKYIzy3c67U6tIpPkFK/VjCuaBtrjOVPv /0=; b=MxKJYFzd9lLPZEOsn0vHjs35cc1ssrkKj8qvgNPWV2hX2XYwZyP8zbxKC qgj/XBt1v36znjl7qDzCXSo8xUykyHnmuFkz498amqkjHqGAaqCb4cQcxt80yB6q 2oByYQBihkn/xEXnfWZwbFRCucWxAhjk0fIpucuMieo6TPA4yveGLn9dyVriTlpX QQWEPGVIVh6xCum0IEuGjiSsEywVdWRihDyPL2DnroRHQMIXigPLEZlI3Oy3YIP5 +TvfBrqZyQEVGkw75G0BKpfwtGIgv5ILKp+SwmrOEBzrqQ8m9xXT6rbKrzTeG5ZQ 0VEeE7eFXnig0GcDa8llImswNcOJQ==
X-ME-Sender: <xms:_rxLYLdiVLGuhHjJBCvVzDT10NFrS2ToKJ1paaEQR1gEeFdh3K6NSw> <xme:_rxLYBOOSEwYCHJkJcuzshPz0FyE5_nglJPaFGT7_vG3UtaYNokX1hSS317YRGV5u _VjYE2Ogcpae8Ba2g>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledruddvvddguddvtdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmd enucfjughrpefofgggkfgjfhffhffvufgtgfesthhqredtreerjeenucfhrhhomhepfdfu rghmucghhhhithgvugdfuceoshgrmhesshgrmhifhhhithgvugdrtghomheqnecuggftrf grthhtvghrnhepfeduudekkeeuteeuleefgeeuvdeuvdffhedvveeiffeghefhjefftdev veeuvdffnecuffhomhgrihhnpehivghtfhdrohhrghenucevlhhushhtvghrufhiiigvpe dtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehsrghmsehsrghmfihhihhtvggurdgtohhm
X-ME-Proxy: <xmx:_rxLYEjobRXvM_QT3mDn0Y4iodBXVySG2DGby6vBjosrDq876KCh0w> <xmx:_rxLYM8CwLWK8Cz-E0cEhYblrUGV9iuGWsV1OSXhoazcAbA-HQFPJA> <xmx:_rxLYHvwXjpPW16vFEJrm0EO3zKwKwUgWdncpSRzUQ40crh0s-KFyQ> <xmx:_7xLYF7N8764cEbab_HRxmq7h8voA8bIvwjni3Yi8DiCwRAkS8SdTQ>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 7E3C7280074; Fri, 12 Mar 2021 14:11:58 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-206-g078a48fda5-fm-20210226.001-g078a48fd
Mime-Version: 1.0
Message-Id: <6762c057-ae0a-42f0-866e-0f107e648617@www.fastmail.com>
In-Reply-To: <1689536526.89782.1615481869806@email.ionos.com>
References: <1689536526.89782.1615481869806@email.ionos.com>
Date: Fri, 12 Mar 2021 14:11:38 -0500
From: Sam Whited <sam@samwhited.com>
To: KITTEN Working Group <kitten@ietf.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/d30C35fdrS8h845dyDKRquQgpwI>
Subject: Re: [kitten] Comments on draft-ietf-kitten-password-storage-03
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Mar 2021 19:12:02 -0000

Sorry, I think you brought this up before and I must have left it out of
the changes. I've made these changes and will fix it the next time I
upload a revision.

—Sam

On Thu, Mar 11, 2021, at 11:57, steve@tobtu.com wrote:
> For the output lengths, pick a number between 16 and 32 bytes
> and stick with that. I'd suggest 16, 24, or 32 but it doesn't
> really matter.
>
> ** Argon2 and scrypt ** Just say "[pick a number] Bytes or default"
> with [pick a number] being what ever you picked.
>
> ** bcrypt ** bcrypt is not a KDF. So you can't pick an output length.
> Thus "Output length: x (internal hash function output length)" should
> be removed as it does not make sense.
>
> ** PBKDF2 ** PBKDF2 should never output more than "hLen (length of the
> chosen hash)" for password hashing. So this should be "Which ever is
> smaller [pick a number] Bytes or hLen (length of the chosen hash)"
> with [pick a number] being what ever you picked.
>
> _______________________________________________
> Kitten mailing list Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>

-- 
Sam Whited