Re: [openpgp] The Argon2 proposal seems incomplete (Draft 6)

Stephen Farrell <stephen.farrell@cs.tcd.ie> Sat, 30 July 2022 16:20 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5BBCC157B43 for <openpgp@ietfa.amsl.com>; Sat, 30 Jul 2022 09:20:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.009
X-Spam-Level:
X-Spam-Status: No, score=-7.009 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rPYLY2scwxKk for <openpgp@ietfa.amsl.com>; Sat, 30 Jul 2022 09:20:15 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30106.outbound.protection.outlook.com [40.107.3.106]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1569EC14F74D for <openpgp@ietf.org>; Sat, 30 Jul 2022 09:20:14 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LAsH5fwXkGG483S5MkFlhBO+d6TU0yClZIWmKWZyKT4fviKdAa3hiSprelLoo3dhrqaoa5FULByzuMY0TSeDvWc0d/WIz66q3GcsfuhwReYQdiZrLPSF9vf8rU2ahjlLiMjBQ0CDnB5YddJXBJIH5WCrPiIpOuH86tqS+5NrkJVwra8+IEr7TBoNyUkOVqhk4PiJH6VsfKhSglusn58PPuMYnK1onozpne3g30BYuty5LSdVvYP4VWudcvSWyMFODOzQorgJKyD5F41LYD2hC7Ae6QCT7UC964jR09Gxop03WYcakTDsI7u31uRblwSy4tPQajoZtsX6ot1Jlh9Dag==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=i+Lfk+Agmw27KOQVIH80GiZUKZPKTOvytX7/eNI0fMo=; b=nVMmsh0MNpcAHtkNIbuhLXnGm2u2INcya5CuVTSI1nxsFN5smcgo+zGMGmYAIoR+hCWahZZnbRmUqhwb3Epv3txnl2U166TfoaVqCjUmBQCLHzDlIWYAfBY3BPd96zhRaJnT839tOJXJ6QcRGmbgtbFOzNYxO2NF7AV/SOTidUm6EVNRCbpXgZUIeiI+RfMWgEdrx5mvBU/8M0TL0Yc/L28cibquf/NsJVznsu+tn6UAZMBiP+7EWDwhgZ5hq/IIOyUt0pLmGnr70KSkz5uQ+NRIsgedIaNRrKiNmcej2pHZG6GtuIZcxgr6lhWWeZ30dxmU3oBoQzoRqmcTdBDqWQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=i+Lfk+Agmw27KOQVIH80GiZUKZPKTOvytX7/eNI0fMo=; b=MdWjKhJm/z+cu9JPWCx+6xJInwOiHYMjZpQNLNaxFqibM56f0bVYlcdMmk4hy/yS5eVM7kcQvf4S0PY3Lj9GbovMCFwLhwfJjE73ETv9zTUFNj91ktJGmni1eL692UbSvZAErH7PmqtfjpLyZGkzqEM9Dv2FW2UvTh6u1Sf7LpPtAINSRLm71CEGQeVLp6KayszvdFT2GwF+E6OMzYP9jDmnAaqo/BXFHmjUe2ZRvFM1igCSqWE82c9UgStErCkgDX0LPT7y1ch6EoCUro3CQqhsvgDgK4kiXVJRcef/sjs3/QoL9T0F5aJf81CsTHn36D/1r30xGK074PrI8EUU8Q==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by DB9PR02MB7291.eurprd02.prod.outlook.com (2603:10a6:10:248::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5482.14; Sat, 30 Jul 2022 16:20:10 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::6595:d554:3f4:9069]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::6595:d554:3f4:9069%7]) with mapi id 15.20.5482.014; Sat, 30 Jul 2022 16:20:10 +0000
Message-ID: <152ab077-e4c9-7aed-8b44-4e999ed19e89@cs.tcd.ie>
Date: Sat, 30 Jul 2022 17:20:07 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0
Content-Language: en-US
To: Bruce Walzer <bwalzer@59.ca>, Justus Winter <justus@sequoia-pgp.org>
Cc: openpgp@ietf.org
References: <YuAErZRsF/KbOw1s@watt.59.ca> <87edy7keb6.fsf@thinkbox> <YuFc+w02FiRQmHcg@watt.59.ca> <87bktajjvq.fsf@thinkbox> <YuKpxp0/Dy1DfC19@watt.59.ca> <875yjhjg2c.fsf@thinkbox> <YuP093G0UKhAJF4U@watt.59.ca>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <YuP093G0UKhAJF4U@watt.59.ca>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------Ts26WvzcgNi5rkfRWYhk3OX1"
X-ClientProxiedBy: DBBPR09CA0026.eurprd09.prod.outlook.com (2603:10a6:10:d4::14) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: b2c8ca86-3ec8-4375-edba-08da72475f61
X-MS-TrafficTypeDiagnostic: DB9PR02MB7291:EE_
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: AOpeY9yWWnHrsKeOo39u4E2OQEqDPDedyXEIsfFFMhQJGt7T7eo6aN4zmcI8KL35DIkwYFM8z0ELwND4Pm3q+czYdt/syUaKaK6bD9pi8j1b2/aE5IhJyZrW7UyZ+Mmef9k5mRSfnnLgCtZRSXtii9Mz/sqH7GhZoOFtdblSGp8alHbvPPGDIg1DiUh1cCHHfvEQERWyDh/uFWmLKKRoyQY3ebRERGxuFUCC6fgUEwXfJLcWCQ7w3JzUhaVHQSF2s74ooJl1vA2XLHLZxCHx6Sg1aPeByVCKqMfw/L45eGTfTCL8HB4/Bu3GAG33JVaVEuqQwVTLHaCOrPDlxJ76x68E+u3ozzNtQOHpUE1qOOxusK5HGiktVUB/PzbhJOPYogyHeU8i6fztDNUAh8CBbLgGs1V1pcuEJLWfZepl1RER3VxehWBLUBkz1Bgz9Y30rE2dt8Pc4H2X8KXDuEpExgoN2tdnrZ7q8fVTQSZ6thsF1Q7fJc1Qg1C7AXhioCtfpPu3Ez8bIGR0OJQgqJWXtr0nie/Qq1TdjQ6tAQIjeiX4zhK1CtwcaM40gyo0ganxtGMZbAyt1sv2gbd3fF6GD7XW3vsiht+h5rRSPefxicsNoZIw4pOkUEobPwS/Ntj4/XuZVZ5Z39YwEUYwPoUazvwOMDkQXV3cW6uBjHrD2/l1AJotEmg92yIG8o/DzGcutmo2S3b+uvc+sMjIlIGU9ZUr6sQZclkJPSWqJKhivse4zX2/GRZlq+QxE/BX6Hfj9cbaWOpKaKxJYouJ8TK50dxeUPIWomqvuf5b08snT0P6sGtJX4VpajYi+rltTUSCQnpdpTutaXkdZNbrgkvUqQ==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(396003)(366004)(136003)(376002)(39860400002)(346002)(5660300002)(235185007)(8936002)(66946007)(66556008)(66476007)(8676002)(4326008)(2906002)(44832011)(38100700002)(83380400001)(36756003)(86362001)(31696002)(478600001)(6486002)(110136005)(316002)(786003)(186003)(2616005)(21480400003)(6666004)(41300700001)(6506007)(6512007)(33964004)(53546011)(31686004)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: tj0XidpDtYpDuHkxrH2Ay0LZEUm2pvQvZrjFm8JXa8XDJfPDy+34vbezZDSXlGktXT+PcPBo/gm4jsiTFydXNcckXNt8jqqIrebcNBbEh8J6wa9fExtN+MBGXbpz1GlJsBjMKrC66vfPYbupgiTvIDSdb+H/VcY1cyt0T1AmHXLxoeafBy1kVJi0JPI64hatuqCYVi9sLqWm/TckIO7hXFjpmwpDgxkimRFZTLpbLWP3UkIUcml9va7QyzBxFLf4swNlq4jAKe4ENgtU6vb1LRjvgPEy8PAqTULM/TQ3RIzhtzfzdR2XHCgqwtYAmUDO9Vf6B8do6WKdFCNJDke61gIC0gznsusAg4DEWZIgelM96SCtLRAETrzVNnJvLARKXGnF7kn3V7tK0Rjvp3XUpH3I3kQHeAqGvLe2tgNaSkZ0T15H4kGIgcMYuN880zitqhYGfPXrTE6kHEAbhJLViTq1OoD7XRJFbK4YWkfBfG+E/JhOOlNbDqj3477gRqdvdFlTSgLhyYeBg2ewghSG1W0sWvoV6puXO1Emb8V/X2xBmatq3YJ6lyBixGDEADfgE2jmpJrjBLcCr62D4ARYqrJ9UqiMOJlRxEx0wOHn7Yj465CYmMskqXZeIiVRpWdXrRvaONRlBNJgg2sAQnAoY1JhknTDsyTAFUuBq+7Thz0OdFcYeawJFptP36aavCnhZZjaF1MIG8sA8iAoaBTAGp5KXfE/JHHwKykUPpAspCmIzxMa4gjlo1sTWK9/IEd5+9PBVhyEzgec4MbXhrUiipq5t/t85oNA2GIwKD1Lm9DI8ixqbVBGHxhQyYpbnXgyx2AC2Nb9x9Mn/bRuxLurOtHZ3G8unpKPp/Jwv4kEplOa1fgmbhW1qMeRyh9s/JvMo98XmXPlL5MXWTwE2yhQs2ib9sFFMEQVZLTJyrhcz6C3+PYuPV6f7qUtLWX9zZPz1KMUAfMhEUK7UAlesPbDhzioYz2CYZYijtEWQwdXIuezpVb3HtXcBsM/e3eqVylgJkCuwmnmz8ed0cBakl8xWKNjw+xn3EQiIzFbDB21p/Ik3rqFulN/9U6Z5u70Iu84+ZdfG394Gbjcd1GZGk+hAIqL0CAqSxbG5yIoUUEr6S3fDXOj5pLxFM5ZRmWORM0hI/K5/uq6B4TBHZs5332xN2AeOF60VznfDe7V4+Lomsju9Spy8MgY3NeUhdm1GbEMkQcMaKXujrJyUq6GQ9js9SmAYu1EnjroiY3oFjcYtBXMoXM/DoSI1Y4dITMrglMyCoGRuR58NcSp0rWHP7Fn3aQNdXRidbmJFnhHzRHbCzpQJOzMXdMA9NlfZyt6IbDjQSA6SqthtZQTJWxCfrY8rc0q2hTB8ckaTvK3+KOGWJwH/Esy5cV4ez93Jw3rIoBWZ5ELFgoGtonsxvSqnltI1Lq+/DgR46B0SHXcH7q8DTDzsRXfdL4H0+QuEE3LF6DMP2S7YLmqZXkRFiXTVnzXu1NUnsOquJ7+N2BZA64fJhruRvuJi94gmyqwV/ik/GfeDkBRgISQSfyhEjpv/SHR1yDwjr7GhRNomjVItObgRyGM89y3JA5YUKmoF7xr+QG+56uqXlWYIgwq6CMpUKKPH096hJldWDZ+tIcEYG9vgzp0m70fZt4A6T89yrZjtdVm
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: b2c8ca86-3ec8-4375-edba-08da72475f61
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Jul 2022 16:20:09.8906 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: A3ZF1C07nKNrfsZb7DtPC2BqrEKmkXCRCkcY1nlDvCY9AjCivBXcSqj9QQKttFTz
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR02MB7291
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/-zPiCS3Lbbf0J-Ju2dULriwBL7U>
Subject: Re: [openpgp] The Argon2 proposal seems incomplete (Draft 6)
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 30 Jul 2022 16:20:19 -0000

Hi,

On 29/07/2022 15:55, Bruce Walzer wrote:
> The issue I am most concerned about is that it appears that the Argon2
> proposal was dropped into the draft without any definite rationale.

As one of the co-chairs, I'm fairly sure that participants
in yesterday's meeting had pretty clear consensus for
inclusion of argon2 in this work. (With chair hat off, I'd
fully agree with 'em.)

It's perfectly fine to try figure out better wording that
describes how to use argon2 and it's unfortunate parameters,
and if it turns out there's some parameter set that might
cause issues for some openpgp implementation/deployment then
that's worth exploring and documenting.

Cheers,
S.