Re: [openpgp] Intent to deprecate: Insecure primitives

Falcon Darkstar Momot <falcon@iridiumlinux.org> Wed, 18 March 2015 07:22 UTC

Return-Path: <falcon@iridiumlinux.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 483DF1A0021 for <openpgp@ietfa.amsl.com>; Wed, 18 Mar 2015 00:22:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pxfMukG5x2zH for <openpgp@ietfa.amsl.com>; Wed, 18 Mar 2015 00:22:21 -0700 (PDT)
Received: from smtp.iridiumlinux.org (akira.iridiumlinux.org [184.70.203.174]) by ietfa.amsl.com (Postfix) with ESMTP id D96741A00A8 for <openpgp@ietf.org>; Wed, 18 Mar 2015 00:22:20 -0700 (PDT)
Received: by smtp.iridiumlinux.org (Postfix, from userid 65534) id E55E513F404A; Wed, 18 Mar 2015 01:21:49 -0600 (MDT)
X-Spam-ASN:
Received: from [192.168.1.135] (unknown [96.53.15.166]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.iridiumlinux.org (Postfix) with ESMTPSA id 172A513F400D for <openpgp@ietf.org>; Wed, 18 Mar 2015 01:21:48 -0600 (MDT)
Message-ID: <5509277D.1080100@iridiumlinux.org>
Date: Wed, 18 Mar 2015 01:21:33 -0600
From: Falcon Darkstar Momot <falcon@iridiumlinux.org>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: openpgp@ietf.org
References: <r422Ps-1075i-0DF0A0ED5D364ECAABA63F541D9C6A16@Williams-MacBook-Pro.local>
In-Reply-To: <r422Ps-1075i-0DF0A0ED5D364ECAABA63F541D9C6A16@Williams-MacBook-Pro.local>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha1"; boundary="------------ms010109080303060703070807"
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/1nFXNiNfo_f2rN9UfyVAo4NSaCk>
Subject: Re: [openpgp] Intent to deprecate: Insecure primitives
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Mar 2015 07:22:25 -0000

I'm not sure this approach scales.

More importantly, I'm not sure it's common practice.  The IETF is at its
best when it is codifying existing practice to promote interop, not when
it's trying to radically change practice with fairly onerous new
recommendations.

Perhaps if anyone desires to modify practice, they should start by
promoting their new approach so that multiple software platforms and the
reference implementation support it.  Perhaps modifications to
open-source mail clients to support a distinction between "wire format"
and "data at rest" and an encryption rollover format would be useful.

On 16/03/2015 10:35, Bill Frantz wrote:
> On 3/16/15 at 6:51 AM, warlord@MIT.EDU (Derek Atkins) wrote:
>
>> Oh, you expected me to decrypt/re-encrypt my encrypted email as I got
>> it???
>
> For many uses, decrypting from the wire format and re-encrypting in
> the "data at rest" security format makes excellent sense. Having only
> one encryption scheme for long-term storage allows easy (relatively)
> upgrade and helps to ensure that the data is still accessible, i.e.
> the decryption still works. I probably have a bunch of old PGP
> encrypted email I can't read anymore because I don't have the secret
> key, or its passphrase. If that mail had been re-encrypted in a format
> that I decrypt every day, I would still be able to read the mail.
> Encryption that isn't regularly exercised gets rusty.
>
> Cheers - Bill
>
> -----------------------------------------------------------------------
> Bill Frantz        | If the site is supported by  | Periwinkle
> (408)356-8506      | ads, you are the product.    | 16345 Englewood Ave
> www.pwpconsult.com |                              | Los Gatos, CA 95032
>
> _______________________________________________
> openpgp mailing list
> openpgp@ietf.org
> https://www.ietf.org/mailman/listinfo/openpgp