Re: [openpgp] Reducing the meta-data leak

Benjamin Kaduk <kaduk@MIT.EDU> Sat, 07 November 2015 20:35 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DF761B3673 for <openpgp@ietfa.amsl.com>; Sat, 7 Nov 2015 12:35:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AEFA5piqsohs for <openpgp@ietfa.amsl.com>; Sat, 7 Nov 2015 12:35:12 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EAAD11B3672 for <openpgp@ietf.org>; Sat, 7 Nov 2015 12:35:10 -0800 (PST)
X-AuditID: 12074424-f79216d00000156e-da-563e607d7ade
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id A2.A9.05486.D706E365; Sat, 7 Nov 2015 15:35:09 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id tA7KZ8gg002180; Sat, 7 Nov 2015 15:35:09 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id tA7KZ5LP014422 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Sat, 7 Nov 2015 15:35:08 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id tA7KZ5ww029935; Sat, 7 Nov 2015 15:35:05 -0500 (EST)
Date: Sat, 7 Nov 2015 15:35:05 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bryan Ford <brynosaurus@gmail.com>
In-Reply-To: <160A8D98-3DF8-4F51-A38C-EF3E0DAE71EE@gmail.com>
Message-ID: <alpine.GSO.1.10.1511071533300.26829@multics.mit.edu>
References: <mailman.92.1446580813.31211.openpgp@ietf.org> <86CB1513-F594-4A9B-A3B6-17ECB9CA9EB6@isoc.org> <160A8D98-3DF8-4F51-A38C-EF3E0DAE71EE@gmail.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-617396658-1446928505=:26829"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprAKsWRmVeSWpSXmKPExsUixCmqrFubYBdmcGKqssXEV3dYLRr+PWR3 YPLYOesuu8eSJT+ZApiiuGxSUnMyy1KL9O0SuDIeH/7LXvCereLxg7vMDYw3WLsYOTkkBEwk mia9YoKwxSQu3FvP1sXIxSEksJhJ4ta01WBFQgIbGCUa/kRCJA4ySfQcfgmVqJd413qBDcRm EdCSuLj4IzuIzSagIjHzzUawuIiAmsSTlv9gNrOApsSLc1OZQWxhASOJuRNmgsU5BWwlbt// CHQFBwevgKPEyb3ZELtmM0p0PJkPViMqoCOxev8UFhCbV0BQ4uTMJywQMwMkfh55wTyBUXAW ktQsJCkIW12i8cFZNghbW+L+zTa2BYwsqxhlU3KrdHMTM3OKU5N1i5MT8/JSi3TN9XIzS/RS U0o3MYICm91FZQdj8yGlQ4wCHIxKPLwbftiECbEmlhVX5h5ilORgUhLlPRVqFybEl5SfUpmR WJwRX1Sak1p8iFGCg1lJhNdRCyjHm5JYWZValA+TkuZgURLn3fSDL0RIID2xJDU7NbUgtQgm K8PBoSTByxYP1ChYlJqeWpGWmVOCkGbi4AQZzgM0XBWkhre4IDG3ODMdIn+KUZdjwY/ba5mE WPLy81KlxHk9QYoEQIoySvPg5oAT0m4m1VeM4kBvCfOGgVTxAJMZ3KRXQEuYgJY4RNmALClJ REhJNTDGfq81ncx9YLVAgcstL+E1L34uyeoUvCFVH7TPo+2B1cMD/yam3eR6vFkv+VI9u+Pr gEX8O6cv6bi67++F6seOdoqfDRgYi5TVNmSZbdCvsNr364JT49MAA34WnbTCxo2fTydJSTSw xDZNCT8/7c/RiLku/yYvjAq5JcC4yVm9/5OZhE+4/0ElluKMREMt5qLiRABwtEXKIwMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/KcmnEtZofmZYSWuOZ6yNQlqu2IU>
Cc: "openpgp@ietf.org" <openpgp@ietf.org>
Subject: Re: [openpgp] Reducing the meta-data leak
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 07 Nov 2015 20:35:13 -0000

On Sat, 7 Nov 2015, Bryan Ford wrote:

> I’m glad to see the metadata-leakage protection topic drawing some interest, including some healthy skepticism on whether it’s practical. :)
>
> I’ll try to summarize my scheme at least somewhat concisely, and include
> this in a draft-of-a-draft that I have in progress.  A bare-bones (i.e.,

If this is the "concise summary", I am not sure that I would want a
software implementing something this complicated in the critical security
path for anything I do.

-Ben