Re: [openpgp] First remarks on the last I-D

Werner Koch <wk@gnupg.org> Wed, 08 June 2022 09:56 UTC

Return-Path: <wk@gnupg.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1182CC14F746 for <openpgp@ietfa.amsl.com>; Wed, 8 Jun 2022 02:56:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=gnupg.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KPp8kLc5U2mn for <openpgp@ietfa.amsl.com>; Wed, 8 Jun 2022 02:56:14 -0700 (PDT)
Received: from kerckhoffs.g10code.com (kerckhoffs.g10code.com [IPv6:2001:aa8:fff1:100::22]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9BE1DC14F728 for <openpgp@ietf.org>; Wed, 8 Jun 2022 02:56:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnupg.org; s=20181017; h=Content-Type:MIME-Version:Message-ID:In-Reply-To:Date: References:Subject:Cc:To:From:Sender:Reply-To:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=iieVSvlWL7M8yopBv3LwzqPOLnbTHhEjcJJ9KvpZit0=; b=MpVu5SrmYuDmHxfhgnu1s9HKr9 /lx3beOK0oEXK52i2Jd8Rj32bXDKtVrOkBDI8UiDZJ/zF8qxxjroimT0b3PmlSkpdUiO9oRAX9mQc sjc61DYjoYavtrGVJM2n6x/ov0xM4ljQl+yGCkhHZxipepVG6n1KFjUh1g5HkP89lfsw=;
Received: from uucp by kerckhoffs.g10code.com with local-rmail (Exim 4.89 #1 (Debian)) id 1nysQ3-0004ao-IS for <openpgp@ietf.org>; Wed, 08 Jun 2022 11:56:07 +0200
Received: from wk by wheatstone.g10code.de with local (Exim 4.92 #5 (Debian)) id 1nysOZ-00006T-PT; Wed, 08 Jun 2022 11:54:35 +0200
From: Werner Koch <wk@gnupg.org>
To: "brian m. carlson" <sandals@crustytoothpaste.net>
Cc: openpgp@ietf.org
References: <165453577116.17285.7902041139949315015@ietfa.amsl.com> <87tu8xkjx4.fsf@wheatstone.g10code.de> <1378eec-4255-930-736-ffd27f292d48@nohats.ca> <87fskgy5c0.fsf@europ.lan> <Yp/t/PlF55TUnpQN@camp.crustytoothpaste.net>
X-message-flag: Mails containing HTML will not be read! Please send only plain text.
Jabber-ID: wk@jabber.gnupg.org
Mail-Followup-To: "brian m. carlson" <sandals@crustytoothpaste.net>, openpgp@ietf.org
Date: Wed, 08 Jun 2022 11:54:35 +0200
In-Reply-To: <Yp/t/PlF55TUnpQN@camp.crustytoothpaste.net> (brian m. carlson's message of "Wed, 8 Jun 2022 00:31:56 +0000")
Message-ID: <87pmjjiip0.fsf@wheatstone.g10code.de>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=AQIM_INR_PCS_TEMPSET_Biological_weapon_Reyosa_Albania_Meta-hackers=C"; micalg="pgp-sha256"; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/51MAmmprtwv2g3FjCFEpWRRkkwI>
Subject: Re: [openpgp] First remarks on the last I-D
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Jun 2022 09:56:19 -0000

On Wed,  8 Jun 2022 00:31, brian m. carlson said:

> agencies and contractors using the older non-AEAD schemes, which is
> substantially worse from a security perspective.  GCM can be optional

That's true for TLS and CMS but for OpenPGP we have our well working MDC
system which has not shown any weakness despite that it predates the
modern AD algorithm.  Thus there is a good and solid system for the time
beeing which is slower than OCB but not necessary much slower than GCM.


Shalom-Salam,

   Werner


-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein