Re: [openpgp] Backwards compatibility

Peter Gutmann <pgut001@cs.auckland.ac.nz> Wed, 25 October 2023 11:09 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 85B99C15106A for <openpgp@ietfa.amsl.com>; Wed, 25 Oct 2023 04:09:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.91
X-Spam-Level:
X-Spam-Status: No, score=-5.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, PDS_BAD_THREAD_QP_64=0.999, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SUcXaQ2kAz-f for <openpgp@ietfa.amsl.com>; Wed, 25 Oct 2023 04:09:27 -0700 (PDT)
Received: from au-smtp-delivery-117.mimecast.com (au-smtp-delivery-117.mimecast.com [103.96.21.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A73FFC14CF1B for <openpgp@ietf.org>; Wed, 25 Oct 2023 04:09:26 -0700 (PDT)
Received: from AUS01-ME3-obe.outbound.protection.outlook.com (mail-me3aus01lp2233.outbound.protection.outlook.com [104.47.71.233]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id au-mta-61-tQkQIICFPHW316DgAOIr-Q-1; Wed, 25 Oct 2023 22:09:21 +1100
X-MC-Unique: tQkQIICFPHW316DgAOIr-Q-1
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com (2603:10c6:10:10b::10) by SYZPR01MB7607.ausprd01.prod.outlook.com (2603:10c6:10:16c::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6907.33; Wed, 25 Oct 2023 11:09:19 +0000
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::8b37:6300:4865:c88a]) by SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::8b37:6300:4865:c88a%4]) with mapi id 15.20.6907.032; Wed, 25 Oct 2023 11:09:19 +0000
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Werner Koch <wk@gnupg.org>, Andrew Gallagher <andrewg=40andrewg.com@dmarc.ietf.org>
CC: Paul Wouters <paul@nohats.ca>, IETF OpenPGP WG <openpgp@ietf.org>
Thread-Topic: [openpgp] Backwards compatibility
Thread-Index: AQHaAcNWce1bknBNTECRs8OPPkd0a7BPx+cQgAATqYCAANi29oAALZaAgABQspKACS/yEQ==
Date: Wed, 25 Oct 2023 11:09:19 +0000
Message-ID: <SY4PR01MB62510E0FC5A6306A861AD0E0EEDEA@SY4PR01MB6251.ausprd01.prod.outlook.com>
References: <CBAF59DC-8F4E-4E1B-979B-6838D4F662E0@nohats.ca> <87jzrjx3jc.fsf@jacob.g10code.de> <774b9eea-1d06-c957-dc21-4457989c896d@nohats.ca> <87r0lrulsw.fsf@jacob.g10code.de> <999A1C80-4DF7-4E6D-BBCC-B17E4A9C60F8@andrewg.com> <87il72vfgz.fsf@jacob.g10code.de>
In-Reply-To: <87il72vfgz.fsf@jacob.g10code.de>
Accept-Language: en-NZ, en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SY4PR01MB6251:EE_|SYZPR01MB7607:EE_
x-ms-office365-filtering-correlation-id: 339838c1-19af-45e1-a7e8-08dbd54ad5ec
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0
x-microsoft-antispam-message-info: Pwjx9B6FLpDAFqiWAZbOc6AayxPHdZg0pbj5ZJWfuSvlVFSaGIUKs2XRwlqPvd67nzhJ7rQwkBfpOU3cKV6fz8TX8LrSqQ/pwbB36PzGkQFjiuYpggbYLhZnXhgFCPgWjgOZifajg2W3SIc5x4bvf1oFQi9Y4IsTvdTRpe+Mjxv84jXMeJqZUWazKTh1dKHf2PXOSJYXYruR7k6K8HaKBGoVcl4Ltwah7HuN81cwNCqxzroUnAPzyUsa9JHIEpPuSz9PaSc+xsVpr4ut//dY7a6XxecJp8yigVQ4gGgzDqK/BmzmngqRH3WYdbJ17KC+zf87FOGgyAPtz1LLwS91vET3ZrAsF/zhuPvsVXSJqpaE7myjxKwsEtsonyXqYzAL7Zj2Q9Jol56EuUHREZ/h8E029NnPs8RhllcAFRoJeuPx1xHdmWZYpfEnYvJkxLvfhd4wwBLpFZUFvC4Vh/37oYsWtde2BFa9wtC/RfpOxkhBNg4TvNDFXUihW8cxYh/5FGuWKsyAW8q8ijHsicfkXeXsNNCdjMc+M53GoIHUhBE2Yt40zqSVlI4LmIFJaFq8vzwCneyMj/KAbJvoVQG/1pb1ntSs6tZUdIhcFBn1ij2YlJU7ho3tOdclteWpjQCG
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SY4PR01MB6251.ausprd01.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(346002)(376002)(396003)(136003)(39860400002)(366004)(230922051799003)(1800799009)(186009)(451199024)(64100799003)(4744005)(2906002)(86362001)(55016003)(38100700002)(41300700001)(76116006)(66446008)(122000001)(786003)(64756008)(316002)(71200400001)(66476007)(54906003)(66946007)(66556008)(6506007)(7696005)(478600001)(110136005)(9686003)(83380400001)(5660300002)(52536014)(33656002)(8676002)(4326008)(8936002)(26005)(38070700009); DIR:OUT; SFP:1101
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: rE8WKEsTvrM+ltJuV6ro/GM+TmkzI9Bo4VrZKv0LnwwSDojkSkWye3DnkF7c/GizmZGG1jEzfWD6O0MFPsPnPpy1w3d+2LZk7ZtUUMpTL5kVUOS+GmtnrEb4X2qQP+qS/lQ48S1svK2yJBgFYOFNerh1NJ9ZUNlvCV1gYWhF1ZJ7z0Urp6UfiMgjxdxMGhZXiKjm9msgjXTpCMgDAQwTB6sSmV4ESOes6BcQR5ShFgq7QZLVslXHwWdjHvGV3cSNJ7mQLzXzQJyK6v4//3CKW+FONbfTvVeykstHVAm9uQZ8rIjpoYwSB+Vk3BmzP+49dRbrp2UM4xHRRLGMzyiSsXZevZcwibOtALVwoqPvProuxQde8lJyQr9YKIoSpzyR0k/KrhiWhqloooLzoLSKnYJg5IxfglGpabBP+xZHMaLyg46HKRSN3dPv5wxZ0gBKywBvgLl9FuvSpjEtkacnXLt3yS0Yxwr0v3kLjbxylaviblDxBkRAyhgZLPVTQ8IZlMzK9cQJ3GXgOysEcLPspZ194wf2YN91z+CX7iD0q0tWGDhyrzRDbHxkvslOuPrO+C6P7/GJwa/BMiuvW7oTHu10Gu/f8gKWpLv7kwy90JqzGa90WvSwppfEqNt1ZPjJxrKyXScU3zZHLGHa1kQKWDUMwzDIefbTPh+wi0nEPdOPgzOnLkmgkdPYU2nBYYDLPf8X+EYVoPR60nWjtc043vh8DBPWVwvJXlgZkwdaTT3p9fwUhTcbRTEUbayGYPlJ4LucSGxIE0R5ycIJonxZ6ueYXvXZw8noZdozE/rDxmtbLDsb9fwpr4iJ7fH0w5oybSgiu96Bf376o5BNoV1+zCmsQ0y+S1UP8JTC48O16ZLVzjCgTijlw4M+vQzmN9M/aKsXMMt/NeW9NkgCpzt5LOMzPW7So4Dug9m9BMbYWlab5yDi0Yp9IzCk74UK/VwCj4eKxcmedr1v/kaT3+eHikSksQoA7Kp6E2vbg/GsJUOCAM0pGtdstjNREJnXAFY7jjxNfq4KMCcye75tiuCvzMLC8yC5YFyCJtEsY7pjSRrAs4K3uuzaOtGA6icymyDEAo2C6jX31+QIY91sOWXq+LprXKhysSbL/WDa/tzwi/OdqbB/mvEY/I3Ou7OaxQCZSt8uf8PzCVazIumDD81tNAiHW7jgxjvWcajDJIjW3C7o8VbdR8Gd15WyNlHpkdACRqmS4k2J8F7eyh3BAJL1rfhZPTRtrMOlMnImnKDS+OBpguEFRfMtzJtAKyVCgchZ0Jh5p0E8589cQyCWg+AXSm/BfbkF3xKCgS8zu1U8coARhud3oevbi8WopK52aC4h7MfUgrra9rjNh8mn0lapbPNJYHjPUOKRql7bG2mh1Xpg+OeTl0J3VuTzZmXIT75gQxbk0UxREAdiAi/UHIcYSJPLARFXsJ1eUoNegnjRsyW6GgUoTOX+BY+K+aUr7kMLeioptnA7NPtwwg/ngdF64uGvYYxyOPNgdhZOPM1aKLxXC8K4Dx70F1JXqjr5PQrp8emdSzrhdJa8U9NgIiqCrE4CVYY4dr0wOZMMglUHQbYm73FCc5Nf9HAVdP859os2
MIME-Version: 1.0
X-OriginatorOrg: cs.auckland.ac.nz
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SY4PR01MB6251.ausprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 339838c1-19af-45e1-a7e8-08dbd54ad5ec
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Oct 2023 11:09:19.6061 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 4xleJ+P37K5kuF4p5H6pKNoeO7woMB67WbNdlT1n64ZQQeBgZjtm0tbIQo6I/5KjHQZsFYXBPwanHX1sbkCEYdF06NQWm1n04ndsdg7t/Ig=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYZPR01MB7607
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: cs.auckland.ac.nz
Content-Language: en-NZ
Content-Type: text/plain; charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/PrHVrd2Q9mCKHfAQHgAXSLpdP60>
Subject: Re: [openpgp] Backwards compatibility
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Oct 2023 11:09:28 -0000

Werner Koch <wk@gnupg.org> writes:

>GCM simply does not belong into OpenPGP.

I think a bit more detail would help here, namely mentioning the fact that GCM
fails catastrophically if an IV is ever repeated.  It's such a common failure
mode that when I'm auditing crypto code one of the first things I do is
cherchez la GCM [*], since it's a great beacon for where the crypto flaws are.
The rule is if GCM is being used then find out of IVs are repeated, or there's
a way to get an IV repeat, or to force an IV repeat.  It's unsafe at any speed
and therefore shouldn't be in PGP.

Peter.

[*] The other one is "cherchez DH being run sideways in an attempt to make it
	work like RSA", which is also a rich source of crypto vulnerabilities.  In
	fact a combination of sideways (static-ephemeral) DH and a fails-on-IV-
	reuse stream cipher almost guarantees some vulnerability somewhere.