Re: [MLS] Unpredictable epochs?

Benjamin Beurdouche <benjamin.beurdouche@inria.fr> Fri, 26 April 2019 14:10 UTC

Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F6C012047F for <mls@ietfa.amsl.com>; Fri, 26 Apr 2019 07:10:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level:
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4YEa3eHc7qob for <mls@ietfa.amsl.com>; Fri, 26 Apr 2019 07:10:12 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DAE8B120481 for <mls@ietf.org>; Fri, 26 Apr 2019 07:10:11 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.60,397,1549926000"; d="scan'208,217";a="304103179"
Received: from 91-165-78-144.subs.proxad.net (HELO [192.168.0.18]) ([91.165.78.144]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 26 Apr 2019 16:10:09 +0200
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <C27BD97E-CC21-4563-9BA6-5E80E946F954@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_2A909498-B7AA-47F7-9E63-B3151E4ECADB"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.8\))
Date: Fri, 26 Apr 2019 16:10:08 +0200
In-Reply-To: <CAL02cgQtF4_gAM1dd+3Vrsi+p-1-R3otRHbOTbiLELVxiuyLVg@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Richard Barnes <rlb@ipv.sx>
References: <CAL02cgSE1xTF2Wsq-u=BCu2Z_4UzMzqMPi=D_H7_7hbRpUMVVA@mail.gmail.com> <2D195D14-9F9A-4D64-92EF-35C601C52C01@inria.fr> <CAL02cgR8gQ6cH_QXd_9v46aJ5aeo=b=1GiYu9YxCNYzJb0tOFQ@mail.gmail.com> <B36BF8F5-EAE9-4C96-A867-82CDFBF830C0@inria.fr> <CAL02cgQ7-JMQsG6sq6YBB3G-5tmCVQoo07nvW63tzBzHPQ0ZWw@mail.gmail.com> <AC74CACD-541B-49CD-9CC9-63343307A53D@fastmail.com> <CAL02cgR98gpF1HqDn31-xxUC6w3Orec_P=2VZ_5jc3xx6uLWCQ@mail.gmail.com> <E984A4FB-DBA9-4B4D-A0F4-A6A5ABEF8ADD@inria.fr> <CAL02cgQtF4_gAM1dd+3Vrsi+p-1-R3otRHbOTbiLELVxiuyLVg@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.8)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/Uh0WBkXFpyMjWyjpODsEK52mvKs>
Subject: Re: [MLS] Unpredictable epochs?
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Apr 2019 14:10:25 -0000


> On Apr 26, 2019, at 3:21 PM, Richard Barnes <rlb@ipv.sx> wrote:
> 
> We might have a problem in any case, then, since the transcript hash doesn't cover the signatures either.
> 

Ok, there might be an issue then, I am quite sure that it was covered at some
point, so it might have been lost. The slight difference with TLS is that some
messages can be discarded from processing (add_send/receive_current_member
or add_send/receive_new_member) while I expect that all of the messages must
somehow be contributed to the transcript-hash to provide the strongest authentication
properties. I’ll have a look into this...

B.