Re: [openpgp] OpenPGP encryption block modes (Was: The Argon2 proposal seems incomplete (Draft 6))

Peter Gutmann <pgut001@cs.auckland.ac.nz> Wed, 03 August 2022 05:54 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB808C15A735 for <openpgp@ietfa.amsl.com>; Tue, 2 Aug 2022 22:54:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.608
X-Spam-Level:
X-Spam-Status: No, score=-2.608 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p9oXzrfAo0We for <openpgp@ietfa.amsl.com>; Tue, 2 Aug 2022 22:54:18 -0700 (PDT)
Received: from au-smtp-delivery-117.mimecast.com (au-smtp-delivery-117.mimecast.com [103.96.23.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D6D1C15A727 for <openpgp@ietf.org>; Tue, 2 Aug 2022 22:54:17 -0700 (PDT)
Received: from AUS01-ME3-obe.outbound.protection.outlook.com (mail-me3aus01lp2238.outbound.protection.outlook.com [104.47.71.238]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id au-mta-18-Bk1tdy_QMGWcxWihwTdVXA-1; Wed, 03 Aug 2022 15:54:11 +1000
X-MC-Unique: Bk1tdy_QMGWcxWihwTdVXA-1
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com (2603:10c6:10:10b::10) by SYBPR01MB6160.ausprd01.prod.outlook.com (2603:10c6:10:107::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5482.11; Wed, 3 Aug 2022 05:54:09 +0000
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::9ce9:9bf2:308b:8a40]) by SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::9ce9:9bf2:308b:8a40%3]) with mapi id 15.20.5482.016; Wed, 3 Aug 2022 05:54:09 +0000
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Bruce Walzer <bwalzer@59.ca>, Werner Koch <wk@gnupg.org>
CC: Justus Winter <justus@sequoia-pgp.org>, "openpgp@ietf.org" <openpgp@ietf.org>
Thread-Topic: [openpgp] OpenPGP encryption block modes (Was: The Argon2 proposal seems incomplete (Draft 6))
Thread-Index: AQHYppFPTkZClEdGQUuCpQywRozOVa2crEn6
Date: Wed, 03 Aug 2022 05:54:09 +0000
Message-ID: <SY4PR01MB6251E8D4ED18EF9EB1497DB7EE9C9@SY4PR01MB6251.ausprd01.prod.outlook.com>
References: <YuAErZRsF/KbOw1s@watt.59.ca> <87edy7keb6.fsf@thinkbox> <YuFc+w02FiRQmHcg@watt.59.ca> <87bktajjvq.fsf@thinkbox> <YuKpxp0/Dy1DfC19@watt.59.ca> <875yjhjg2c.fsf@thinkbox> <87r124m64c.fsf@wheatstone.g10code.de> <YulX9jI1+wOCwLJq@ohm.59.ca>
In-Reply-To: <YulX9jI1+wOCwLJq@ohm.59.ca>
Accept-Language: en-NZ, en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d52dec77-2af4-40cf-410d-08da751495a7
x-ms-traffictypediagnostic: SYBPR01MB6160:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0
x-microsoft-antispam-message-info: o+7j8s4VqgZtk6DotPtdfm44V/Z6SZVGuQdIOLl3Ecm2DcYKyCwz7PkuCKLmsXxZWhHGivgjAduqU3c9TJ/rZbnE/41W6JwijeNQ5jjp1qSxA189ZESRizPKB5d5pMQ6b3ckounvNNBylXNKVA4E6TY/jajQ/SLDFLA7VQCW6sKLy4AkWVJOk7BrLuV7WyZkzbkfDqaLiH3KPigrrd1jWXCOq4BVo3Cx0hpjPe3c8qB7zs3hDdbJQ4HvAXoWJihapZKXDzbwcjLnUr5h6q8fOeGBY6SUnG7sNwhrBVNgyanOSS8yRN1ZQwbvYiDquKbD1bm2UzD7R9mA0xxwA7o8pq8LwfYDfVDcPAW8vD89bzqzmq+CTa0OEpiAOh2YBLwg+ftcxtbCao9VP/p4gq1yEeVfR2ZDb20yNFoUIajA9Enbfg4NFO4NPDHLnPoTQ7A17yDDj/bVLFBai0cqzKDjzM5bxmQMPEIMNjNkJKA5NCIZZjUqiAp9u4ehLEUFW3VACNJOd/byXEg5zzAbl8D3akR4mD/bKwNYpIwJ1Q8RPOyTx8EsD8cckfeF/1Jj1qlIXK5kwJiyfc2ECg+Z/kcTQOdRe4vOBiTvreVf8LD07OOITWlHOjoOLDOLfHYPN30fQgZ+RJz3EQL9la7CDbcAXf6vO2SlHWoARSO5OyEsLiFnyRi34lbbMqiJAm5IjUXw21ZgFQq9ixpnEsqHnY055KPXSUztMfRHSTSLwNjhTehsjecPF7qQsOtM7CfZvAUNYC8NvhxSwUXkUevM1+A6MHTn0/eIuIEcdQ5397kT00Q=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SY4PR01MB6251.ausprd01.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(39860400002)(346002)(136003)(366004)(396003)(376002)(7696005)(41300700001)(6506007)(26005)(9686003)(478600001)(316002)(786003)(55016003)(86362001)(110136005)(54906003)(71200400001)(38100700002)(38070700005)(122000001)(66446008)(4326008)(186003)(4744005)(2906002)(76116006)(66556008)(5660300002)(8676002)(8936002)(33656002)(66476007)(52536014)(66946007)(64756008); DIR:OUT; SFP:1101
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: qepZYIN+uG/3NwLaRGErU8d51qqZOeR5r7CB8z2BGY+EXFTNSZDttiow+Pv5Aie58OXoils7lyryhXRO7Io9yvafWKs2lwym2vUuJtvdcLd9pO7JcmTCSI5P38/BmxhGeTa7jFrNBjrSMcOKfABWY7umsFCa75MisS97hc9wblWNvaKe1ooYFCdNtEonEe2WR5P8YgNTn0pOnc1kp3Cco/4o1fQQSoMjjdfg4wKLSVETQBbTAC6V4AvZjuEO/rq9nsaaPa8HbMdnnFnnidc39cKvXPpxyMshPQwlv+TDHDWokzm7VT/fbyj1Xd2IgLph4AVsdi2W/ylovFRwFIYfaYISxHRGVg3sPXgQ2k/8Lph4Ll8FMF5zn7mLvmT0cjaxV8Xo44hAz/OqCDZOFZ4xaR+VwmWG6DjDAnhuL9QLHoCIf+l5y1vJzOSh8w61eNDs46sYqo08739ujMrkE5NIRbZA92JfN4SV/f7/hVkiIT8Spk5N73GFqlBN/z1h473AGMrpRfrgkp2YqzIpyQn4tOrCviTRl5y9c5dQtckjveR7iXJKz248xbRqsKTD78HtQUKRq1yAjTGZlVWYzpl/jwgZs0UcsszuepQHJzhdt2Gw0dFE3XQTn566B1yH1DXobvED4OHZQ61WV5dQ877ZjSh694sROgPTsWGM6+4odgw4Vr556SmeqdRFVnDnvjlGJdD2ZIrQ+XgNnzddUUcLqgt7gVl++AWloFWu40W5soa9y3dMX2UfIN3JprPwyejD+YTi9qV5f+IiBbizPQ7YWRJslC7a9npfyF9mi7pRxFHAMiyUReEIYthc+JgK8rCdoy11opOB4ug3ZsWyEjYh0OBfHh4DBSqk8M+e7GqmlO3NwrfaE7vnBaj3u6qt8Br6gHVJAqbZaFQ+GQ3NgcNw12bvyYAUwxfYi3kr+brq4ngMAe5NEFk6/leVeoUFR8avB2vAjeH3en1i7vK0ZEITGU8/4ynhiBdDXEOqkeQui2lFhCHgrtQILN9ol3ujZVewUh6kzGIanhCPU27np2O3LxKsl84ZER34RMcXhxf8ofLl/9SBB/J0u6M4OTLEeaYTubfQ1T8PYcaXtGRHodo2uLAvBsMFLgrthBNBudnWhyu67sm2ZOZ73O6tWHcdap5jzZ45gm5Q5avAr/5+ES+TPBiWEcD4QfZyAuaQD/VHIIFyH+mzH+pNdU63ftBddSXx5GfAHBZ6wT0a+rvW+37LyFFMdur/v2r73rSQY5hByqaviNq5apDjBgrLy7HQLca1NnLM7gCjQopX9F5g45VlPYZYa2kM7dD3+UDyC1HfxOSycprCWmYxJCR3OWdIORfSshBe1a7+B4I4+x7YK3smefaM+5e6ehdMShZj3213odOioVlExN+GRgAj6m4Zs1nOwyCgLK+KA8cT40ByKJgXeJqrLv+PCn+Qgs+wLmAzNwBjlrcP4XlfRbTGk+ucgqJAi3TUp2IqY2lJBC2NjvQbWG5Cf/ZPPF13ArumQek4axC26nsx4C5+gPHXNbXd4xQdV7/Ft09zorePLnwuINc+4ygFljcrI/xFfaS6FPc9ge5WGFX0wGa6rsEGqN6PCpnYMG41SIzpUnwWvPS2L/6i4g==
MIME-Version: 1.0
X-OriginatorOrg: cs.auckland.ac.nz
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SY4PR01MB6251.ausprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d52dec77-2af4-40cf-410d-08da751495a7
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Aug 2022 05:54:09.6284 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: OGZTurSpBa52t2FL3rF9/iIplg3j6Nez4DEQh9fPyJdIVauCeghRpDJkVMvFeuaugES65c7hAy4HyiloWcojPEABk7SyrXMl38+14uxfd2o=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYBPR01MB6160
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: cs.auckland.ac.nz
Content-Language: en-NZ
Content-Type: text/plain; charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/O_1vBvmMd10H6i38hwyB_jeWjb8>
Subject: Re: [openpgp] OpenPGP encryption block modes (Was: The Argon2 proposal seems incomplete (Draft 6))
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Aug 2022 05:54:21 -0000

Bruce Walzer <bwalzer@59.ca> writes:

>[...]

Everything Bruce said, with the additional comment that GCM's, and related
modes like CCM's, main reason for existence was the patents on modes like OCB.
Now that the patents have gone away there's no reason to prefer the
incredibly brittle and significantly less efficient GCM (or CCM) over OCB.

Peter.