Re: [openpgp] Mining protection in fingerprint schemes

Peter Gutmann <pgut001@cs.auckland.ac.nz> Sat, 09 April 2016 13:55 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 950A812D6CF for <openpgp@ietfa.amsl.com>; Sat, 9 Apr 2016 06:55:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L_LDCvmcX95c for <openpgp@ietfa.amsl.com>; Sat, 9 Apr 2016 06:55:46 -0700 (PDT)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D5EE12D694 for <openpgp@ietf.org>; Sat, 9 Apr 2016 06:55:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1460210145; x=1491746145; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=sNqyVR9OKxllhD3Fq3rB606THidndPUtzK2L2pd0z9Y=; b=fnEDIqPbRejrFPR5OJFyJ4O31ZbyZLqXsaa74bQgE4KvmNE48oXqIUKt cOTN+nzUc5OoKvtQEilxXSnmB+lIj7zjz3dxgDZfc/WDLFKlKBafDqNlL xWk+p6AGGZirgFvVqMWWEMMTW5zoZ/qXaGuMPJIVNMQfa50H+eOVdMRet bXdSLoC6oWCM8VYrnTLkQPRbkn3ARjf5UkPm1SZXvK6/5Vos1VJmSbK4Z m+uLLRBXmgH/VaGkr1Coc/23YkLPc0Xgw3Io67qKmDzm78cAaUonsTG3r lTSGVhqn4LwQvaHSYl65bL6BM6NwBgFuX9vbVm6y6mQvglSOrs55clq5c g==;
X-IronPort-AV: E=Sophos;i="5.24,454,1454929200"; d="scan'208";a="79124462"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 130.216.4.171 - Outgoing - Outgoing
Received: from uxchange10-fe4.uoa.auckland.ac.nz ([130.216.4.171]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 10 Apr 2016 01:55:43 +1200
Received: from UXCN10-5.UoA.auckland.ac.nz ([169.254.5.33]) by uxchange10-fe4.UoA.auckland.ac.nz ([169.254.109.63]) with mapi id 14.03.0266.001; Sun, 10 Apr 2016 01:55:42 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: "brian m. carlson" <sandals@crustytoothpaste.net>, "openpgp@ietf.org" <openpgp@ietf.org>
Thread-Topic: [openpgp] Mining protection in fingerprint schemes
Thread-Index: AQHRkD712bG2iqLU6EOL6HNGn5mjH598wM8AgAEQngCAAc4v04AAOC2AgAHWfV0=
Date: Sat, 09 Apr 2016 13:55:42 +0000
Message-ID: <9A043F3CF02CD34C8E74AC1594475C73F4C52D38@uxcn10-5.UoA.auckland.ac.nz>
References: <4C08CDDD-4C06-41AD-9797-7DD6F08ECD06@gmail.com> <2AA5B912-0AE6-4722-8BC7-66E37559C0B1@callas.org> <D17B23A3-633F-4E4E-BC14-69ED6060F357@gmail.com> <9A043F3CF02CD34C8E74AC1594475C73F4C46D17@uxcn10-5.UoA.auckland.ac.nz>, <20160408215053.GA191287@vauxhall.crustytoothpaste.net>
In-Reply-To: <20160408215053.GA191287@vauxhall.crustytoothpaste.net>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.6.3.2]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/DCNjHvY7xzLChWydQvqmxkWbY-k>
Subject: Re: [openpgp] Mining protection in fingerprint schemes
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Apr 2016 13:55:50 -0000

brian m. carlson <sandals@crustytoothpaste.net> writes:

>The approach I like is what OpenKeychain is doing with QR codes: you scan the
>QR code, which contains the fingerprint.  No manual verification is
>necessary. We should design systems that make it easy for people to get
>right, instead of trying to defeat people being lazy.

Exactly, leave the computation to the computers.  No human should be expected
to compare 40 hex digits for an exact match, that's why we have computers.  In
fact the denser QR codes can store an entire key in the QR code.  Once it's on
your phone, you can use your method of choice to get it to other devices.

Peter.