Re: [openpgp] [PATCH] RFC4880bis: Argon2i

Joseph Lorenzo Hall <joe@cdt.org> Tue, 03 November 2015 09:47 UTC

Return-Path: <jhall@cdt.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A130F1B3143 for <openpgp@ietfa.amsl.com>; Tue, 3 Nov 2015 01:47:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.378
X-Spam-Level:
X-Spam-Status: No, score=-1.378 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rqb8G5LHXVlc for <openpgp@ietfa.amsl.com>; Tue, 3 Nov 2015 01:47:35 -0800 (PST)
Received: from mail-lf0-x242.google.com (mail-lf0-x242.google.com [IPv6:2a00:1450:4010:c07::242]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E234D1B3115 for <openpgp@ietf.org>; Tue, 3 Nov 2015 01:47:34 -0800 (PST)
Received: by lffz202 with SMTP id z202so1176239lff.3 for <openpgp@ietf.org>; Tue, 03 Nov 2015 01:47:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cdt.org; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; bh=NtlLbtFXEcCoI+XEOmHnXI+l9CwG8mJgIRvhA28aBk8=; b=MsJb6eUj+m+gnrkZCdn6AXhy2BfYeAzEG7NfNuhDJ8ye0fQVeCloSae1H/lgYXhxZb h3pH+TyEaz3rKsjJa3/rnr+PrBcQvN8MCB4cBjOw4YvEUFQIDINKcs30wqLIGprwXLxA 6WfbozWwazynYl5+GBFBpH6+9NzcbsB1GS/TM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=NtlLbtFXEcCoI+XEOmHnXI+l9CwG8mJgIRvhA28aBk8=; b=iHHZZnU96wMnN4N2CmHc3neqsLlMEN7LYY2jOcDyJ5g5JsQSwpyA4/O33ZQprdrGeb dpnPBkyzc6GBjWnDhII36kUQ45yCai3IZV4uHj2CBDimxonp5+XN1NpLQA0S3t6FOuWL 5wIj5IikPi+HvOmrnGZHLfWsL0aWkqhWPQ29trG0i1H3oEo1uzBtuXZr49Fu632C5eql CncDTkBrXD5fuLSXbUjFrFlr2OXizSGYjWQho0FShDhYpaKtQM1XEFkj0auD7HJatrS4 v0sO0SoQhcApDDz1ma0vM39dEQqeJcFohZnm4vacT7IsFrH3KbqgGFDwgh8tTylzhnL3 GWFg==
X-Gm-Message-State: ALoCoQnNHDG68sXoUkqSmD8/Z1Y4T0wLXcdgCzfR41esymMGiFpKdLPq1dy8/tMrtCmJJQwSS7fU
X-Received: by 10.25.20.24 with SMTP id k24mr8263301lfi.117.1446544052556; Tue, 03 Nov 2015 01:47:32 -0800 (PST)
MIME-Version: 1.0
Received: by 10.25.141.77 with HTTP; Tue, 3 Nov 2015 01:47:12 -0800 (PST)
In-Reply-To: <20151103092006.3cd3e900@latte.josefsson.org>
References: <5623AA95.4060903@googlemail.com> <874mh3q3ol.fsf@alice.fifthhorseman.net> <56385818.2000606@googlemail.com> <20151103092006.3cd3e900@latte.josefsson.org>
From: Joseph Lorenzo Hall <joe@cdt.org>
Date: Tue, 3 Nov 2015 18:47:12 +0900
Message-ID: <CABtrr-W_24_CumkdGuxW4Ve=NUA_7qa0v=utbaWN0CDoodhfpw@mail.gmail.com>
To: Simon Josefsson <simon@josefsson.org>
Content-Type: text/plain; charset=UTF-8
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/RBJ_EN7Yl536IBouowUup59wuRo>
Cc: Nils Durner <ndurner@googlemail.com>, alex.biryukov@uni.lu, "openpgp@ietf.org" <openpgp@ietf.org>, khovratovich@gmail.com, dumitru-daniel.dinu@uni.lu
Subject: Re: [openpgp] [PATCH] RFC4880bis: Argon2i
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Nov 2015 09:47:36 -0000

At IETF94 one question that came up in trying to move quickly to
support Argon2 is the potential IPR that might be in Argon2. The code
available now [1] is CC0 which, AFAICT, doesn't have any patent grant
or implication for patents, etc., meaning the authors could still
claim something, precluding it from use without a waiver (or whatever,
IANAL)

I'll CC the Argon2 authors (on the Argon2 spec [2]) here and see if we
can clarify any potential IPR and whether that might affect using it
in the future in OpenPGP.

best, Joe

[1]: https://github.com/p-h-c/phc-winner-argon2
[2]: https://password-hashing.net/argon2-specs.pdf

On Tue, Nov 3, 2015 at 5:20 PM, Simon Josefsson <simon@josefsson.org> wrote:
> Den Tue, 3 Nov 2015 07:45:44 +0100
> skrev Re: [openpgp] [PATCH] RFC4880bis: Argon2i:
>
>> Hi Daniel,
>>
>> > If we introduce this as a normative dependency for OpenPGP, though,
>> > we might also want to have an IETF RFC for Argon2.  Do you know of
>> > anyone working on such a draft?
>>
>> Simon Josefsson has expressed interest in helping with that.
>> @Simon: are you working on this?
>
> I started on an Argon2 draft but after talking to the Argon2 team we
> decided to wait until Argon2 was finalized.  I suppose now is a good
> time to resume that work.  I'll put something up on gitlab.com so
> people can review and help.  If anyone wants to help, please let me
> know and we'll coordinate something.
>
> /Simon
>
> _______________________________________________
> openpgp mailing list
> openpgp@ietf.org
> https://www.ietf.org/mailman/listinfo/openpgp
>



-- 
Joseph Lorenzo Hall
Chief Technologist
Center for Democracy & Technology
1634 I ST NW STE 1100
Washington DC 20006-4011
(p) 202-407-8825
(f) 202-637-0968
joe@cdt.org
PGP: https://josephhall.org/gpg-key
fingerprint: 3CA2 8D7B 9F6D DBD3 4B10  1607 5F86 6987 40A9 A871