Re: [kitten] considering abandoning CTS mode (Re: I-D Action:draft-ietf-kitten-aes-cts-hmac-sha2-01.txt)

"Henry B. Hotz" <hotz@jpl.nasa.gov> Mon, 19 August 2013 18:52 UTC

Return-Path: <hotz@jpl.nasa.gov>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E33C11E82BA for <kitten@ietfa.amsl.com>; Mon, 19 Aug 2013 11:52:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mAq7CZUQJlKk for <kitten@ietfa.amsl.com>; Mon, 19 Aug 2013 11:52:47 -0700 (PDT)
Received: from mail.jpl.nasa.gov (mailhost.jpl.nasa.gov [128.149.139.105]) by ietfa.amsl.com (Postfix) with ESMTP id 7E60821F9AFE for <kitten@ietf.org>; Mon, 19 Aug 2013 11:52:47 -0700 (PDT)
Received: from laphotz.jpl.nasa.gov (laphotz.jpl.nasa.gov [128.149.133.44]) (authenticated (0 bits)) by smtp.jpl.nasa.gov (Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.1) with ESMTP id r7JIqcXC021459 (using TLSv1/SSLv3 with cipher AES128-SHA (128 bits) verified NO); Mon, 19 Aug 2013 11:52:38 -0700
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 6.5 \(1508\))
From: "Henry B. Hotz" <hotz@jpl.nasa.gov>
In-Reply-To: <C63BB21E-F976-401D-9130-1E226F1E4E12@jpl.nasa.gov>
Date: Mon, 19 Aug 2013 11:52:45 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <E7D5AE20-B9E5-485A-A16A-75417E0780AC@jpl.nasa.gov>
References: <5674376E76F88641AD3748A64F0996971AAA4F35@TK5EX14MBXC285.redmond.corp.microsoft.com> <tsly584dyzt.fsf@mit.edu> <5674376E76F88641AD3748A64F0996971AAB7DA1@TK5EX14MBXC285.redmond.corp.microsoft.com> <CAK3OfOgRH88DmtAJw=hgd-t7-Sac3xTf-kD+aYOUCDh79AOtkg@mail.gmail.com> <ldv7gfnfxcv.fsf@cathode-dark-space.mit.edu> <C63BB21E-F976-401D-9130-1E226F1E4E12@jpl.nasa.gov>
To: Tom Yu <tlyu@MIT.EDU>
X-Mailer: Apple Mail (2.1508)
X-Source-Sender: hotz@jpl.nasa.gov
X-AUTH: Authorized
Cc: "kitten@ietf.org" <kitten@ietf.org>, Michiko Short <michikos@microsoft.com>, Sam Hartman <hartmans-ietf@mit.edu>
Subject: Re: [kitten] considering abandoning CTS mode (Re: I-D Action:draft-ietf-kitten-aes-cts-hmac-sha2-01.txt)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Aug 2013 18:52:52 -0000

I was unclear.  It affected AES-192, just much less.

On Aug 16, 2013, at 5:31 PM, "Henry B. Hotz" <hotz@jpl.nasa.gov> wrote:

> 
> On Aug 14, 2013, at 8:26 PM, Tom Yu <tlyu@MIT.EDU> wrote:
> 
>>> Also why SHA 384 instead of 512?
>> 
>> I asked Kelley about this, and he said the Suite B mandate was for 128
>> bits for lower security, and 192 bits for higher security.  That would
>> imply SHA-384 (I think HMAC-SHA-256 should be sufficient, but they
>> want an unequivocal 192 bits of strength).  I don't know why Suite B
>> doesn't specify AES-192 instead of AES-256 though.  Maybe these
>> rationales should be included in future revisions.
> 
> There was some post on saag about AES-256 now being only 119-bits effective strength?  I confess I never backtracked the source material.  The problem didn't affect AES-128 and AES-192 much less.
> 
> ------------------------------------------------------
> The opinions expressed in this message are mine,
> not those of Caltech, JPL, NASA, or the US Government.
> Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
> 
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten

------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu