Re: [saag] AD review of draft-iab-crypto-alg-agility-06

"Salz, Rich" <rsalz@akamai.com> Mon, 27 July 2015 21:48 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B77681B349F for <saag@ietfa.amsl.com>; Mon, 27 Jul 2015 14:48:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.711
X-Spam-Level:
X-Spam-Status: No, score=-2.711 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tUlwlz7CmSod for <saag@ietfa.amsl.com>; Mon, 27 Jul 2015 14:48:30 -0700 (PDT)
Received: from prod-mail-xrelay06.akamai.com (prod-mail-xrelay06.akamai.com [96.6.114.98]) by ietfa.amsl.com (Postfix) with ESMTP id 394411B3499 for <saag@ietf.org>; Mon, 27 Jul 2015 14:48:29 -0700 (PDT)
Received: from prod-mail-xrelay06.akamai.com (localhost.localdomain [127.0.0.1]) by postfix.imss70 (Postfix) with ESMTP id EEC8116A851; Mon, 27 Jul 2015 21:48:26 +0000 (GMT)
Received: from prod-mail-relay09.akamai.com (prod-mail-relay09.akamai.com [172.27.22.68]) by prod-mail-xrelay06.akamai.com (Postfix) with ESMTP id D8BE416A850; Mon, 27 Jul 2015 21:48:26 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=akamai.com; s=a1; t=1438033706; bh=NS/47E3Gu/Vvoi+OrBLOlij+ge/7+SNN9ZEod72yw7o=; h=From:To:CC:Subject:Date:References:In-Reply-To:From; b=axiwZiaWsYinRUMHIw/HEDNXPtSrXhzzjNSbQmeKqzU8e0wR5pbbQ/8lTcUBsnJgp ahSVS9b1Qos/PENNXFFF+dghIvjFUhWMeYrTwYUoxVe9FIxcL7sTsddVySHSelGL8O LnMGqKyBulXAF+EB3g1rODvbKiXHXK+w8gXpCYbA=
Received: from email.msg.corp.akamai.com (ustx2ex-cas4.msg.corp.akamai.com [172.27.25.33]) by prod-mail-relay09.akamai.com (Postfix) with ESMTP id D408D1E084; Mon, 27 Jul 2015 21:48:26 +0000 (GMT)
Received: from USTX2EX-DAG1MB2.msg.corp.akamai.com (172.27.27.102) by ustx2ex-dag1mb2.msg.corp.akamai.com (172.27.27.102) with Microsoft SMTP Server (TLS) id 15.0.1076.9; Mon, 27 Jul 2015 16:48:26 -0500
Received: from USTX2EX-DAG1MB2.msg.corp.akamai.com ([172.27.6.132]) by ustx2ex-dag1mb2.msg.corp.akamai.com ([172.27.6.132]) with mapi id 15.00.1076.000; Mon, 27 Jul 2015 16:48:26 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Nico Williams <nico@cryptonector.com>
Thread-Topic: [saag] AD review of draft-iab-crypto-alg-agility-06
Thread-Index: AQHQwLSnXY8Yt1B6m0K40qV2UUv5FJ3hOl6AgA7gMICAAAQLAIAACkYAgAAEnwCAAAUSgIAAAsKAgAADngCAAANggP//rYMw
Date: Mon, 27 Jul 2015 21:48:26 +0000
Message-ID: <9aceb3102c1341929bc4c47c7ef9766e@ustx2ex-dag1mb2.msg.corp.akamai.com>
References: <55A938F1.9090404@cs.tcd.ie> <CD936D80-BEA2-4918-828C-E3A392761EC5@gmail.com> <20150727194020.GD15860@localhost> <55B68C8A.3080006@cs.tcd.ie> <20150727203136.GL4347@mournblade.imrryr.org> <55B69908.2030803@cs.tcd.ie> <20150727210616.GC29423@localhost> <55B69F99.6030009@cs.tcd.ie> <20150727212905.GD29423@localhost> <55B6A577.1080509@cs.tcd.ie>
In-Reply-To: <55B6A577.1080509@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.33.243]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/0Tz4dV1z2pr_kFSOUnC_iH2POIY>
Cc: "saag@ietf.org" <saag@ietf.org>
Subject: Re: [saag] AD review of draft-iab-crypto-alg-agility-06
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Jul 2015 21:48:31 -0000

> My concern is that workfactor will be small enough in a few years that mail
> traffic encrypted today will be essentially treatable as cleartext by the most
> capable adversaries. While the rc4 encryption will add some cost, I'm
> concerned that'll be too small (again, in a few years).

My timetable is shorter (two, not a few) but I agree.

The national-scale adversaries are already scooping up all traffic.

I used to be highly skeptical of post-quantum crypto, but now I want something like whyte's PQ mixin stuff today.