Re: [saag] I-D Action: draft-birk-pep-trustwords-00.txt (fwd)
Yoav Nir <ynir.ietf@gmail.com> Fri, 23 February 2018 17:05 UTC
Return-Path: <ynir.ietf@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80C5A1241F3 for <saag@ietfa.amsl.com>; Fri, 23 Feb 2018 09:05:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9aBtMvOEVUf3 for <saag@ietfa.amsl.com>; Fri, 23 Feb 2018 09:05:22 -0800 (PST)
Received: from mail-wr0-x22f.google.com (mail-wr0-x22f.google.com [IPv6:2a00:1450:400c:c0c::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4596B1200B9 for <saag@ietf.org>; Fri, 23 Feb 2018 09:05:22 -0800 (PST)
Received: by mail-wr0-x22f.google.com with SMTP id 34so14787138wre.13 for <saag@ietf.org>; Fri, 23 Feb 2018 09:05:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=UWl0mvH3tjMzgBtCUD8uHhkFEU/BlAnO6cMDCJS8hDs=; b=WeiZNbAV45aLFLfVB3PvDD17QdFrp3VDLc0KeKdCX/8wy7N9mA6CtN55oNOxFwgoUU amEuROLRp1Oz+NIvJERyllWuexvNfg5sMKW3l5+QciSw+3GKvr0yaDu4mnf/W8R+IS/6 QKcqSKTfuareJ+WvU3nHsyaBrp51eMbMFupv3+5REPRJ7Tvamb+8rXX2MR20jwF13+tI B45tvqk8T4rcv/HnAYVS/lmn2+X9MNiUt4LvrGV9byZ8O6530lZvYLTjFYFrukJV1+cJ AlRShf0R6zTZP1Z3xRyk9MQfaTex1qLM2ob1jsbHIUoLmPippsJUO6eHMWXLFN/hdCSg WY+w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=UWl0mvH3tjMzgBtCUD8uHhkFEU/BlAnO6cMDCJS8hDs=; b=CfgtlxIYpCxjyYvEkKcMK7OO48f63+U0iiq6mfbBYFXotr1VQUthyPlHm7CaE4mBt9 qUzM4/W5+PTAmbzk4rSy/dGdgx1YXNNoc1Y7l56GBcy/tpyLLzAS4GCZw2A6gR9jMHcX WoWWvNf4/XxqOO967rD4ivvYcQzo31HIv/opIFxKB/o+n3tFlTOoipE4n4DVTpQQxckl ETQ+SISUVGYG8B92plxADy2dypAkOqaGhKxDbYrbch15RCblfejV/h60nos83Bt9ztR7 CauYv8IwrHjkfuLLJHQJHAPUJVW7tJpweOFAlRWxAcE+d5jFVFaNSckhOwqDfG64LGey 5x3w==
X-Gm-Message-State: APf1xPDPs7SQz4gcrjuWRdJJluKiDFNTNGFvZIzxN724FmZZ2cLCeA+P M0WvhePFnG0hRmPhhsoXFl3hoOb+
X-Google-Smtp-Source: AH8x226MFby9HwfEMsERzJpY4zoNQyDghiJovctWU+iuJXPq3RM98sxoVVWg/45VTaknZkl6cYnbUQ==
X-Received: by 10.223.192.72 with SMTP id c8mr2375089wrf.145.1519405520796; Fri, 23 Feb 2018 09:05:20 -0800 (PST)
Received: from [192.168.1.18] ([46.120.57.147]) by smtp.gmail.com with ESMTPSA id q15sm2980110wra.54.2018.02.23.09.05.19 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 23 Feb 2018 09:05:19 -0800 (PST)
From: Yoav Nir <ynir.ietf@gmail.com>
Message-Id: <CCF3FA05-38E8-4093-9EFB-902A7B12F555@gmail.com>
Content-Type: multipart/signed; boundary="Apple-Mail=_8546FDF2-FF3D-4D99-83A5-F526E1D623EA"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
Date: Fri, 23 Feb 2018 19:05:17 +0200
In-Reply-To: <alpine.DEB.2.20.1802231543490.29520@softronics.hoeneisen.ch>
Cc: Security Area Advisory Group <saag@ietf.org>
To: Bernie Hoeneisen <bernie@ietf.hoeneisen.ch>
References: <alpine.DEB.2.20.1802231140470.24956@softronics.hoeneisen.ch> <2140FE22-38DB-4545-B623-D1121DA281D1@gmail.com> <alpine.DEB.2.20.1802231543490.29520@softronics.hoeneisen.ch>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/Pj_DQMrBT98fGDd0aegX_YneD-U>
Subject: Re: [saag] I-D Action: draft-birk-pep-trustwords-00.txt (fwd)
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Feb 2018 17:05:25 -0000
Hi. At a former employer we used the function described in RFC 1751 to show a user the CA or server fingerprint so as to make sure that their VPN client was connecting to the correct server. It would be used as part of the instructions for the user: Type in “192.0.2.5” or “vpnserver.example.com <http://vpnserver.example.com/>” at the server box, click “Connect” and you will see a fingerprint field. Make sure it says “TIDE ITCH SLOW REIN RULE MOT”. This has proved OK for ordinary non-technical users, but I can’t be sure any of them ever compared the strings. It’s easier to just click OK. Similarly for point #3, I don’t think either of them calls for the user to write anything down, except in the instructions from the administrator. BTW: even if you make sure your dictionary contains only innocuous words (no swear words), the combinations sometimes can be open to interpretations: HERO JAKE LAID JAIL BAIT GLAD can come out of the algorithm in RFC 1751. Anyway, I think your draft should reference RFC 1751 and state these differences. Yoav > On 23 Feb 2018, at 17:06, Bernie Hoeneisen <bernie@ietf.hoeneisen.ch> wrote: > > Hi Yoav > > Thanks for you email. > > This work is different from RFC1751 in many ways, e.g.: > > 1) The target audience for this new work to use are ordinary human users, i.e. not technical stuff (or IT geeks) only. (Even grandma shall be able to use it.) > > 2) The hexadecimal (sub-)strings mapped into a single trustword are longer. This results in fewer trustwords to compare, but more trustwords in the dictionary. > > 3) The keywords are only read (and compared), but not written down by humans > > 4) The keywords will be available in many languages as opposed to English only > > Does this answer you question? > > All the best > Bernie > > -- > > http://ucom.ch/ > Modern Telephony Solutions and Tech Consulting for Internet Technology > > > On Fri, 23 Feb 2018, Yoav Nir wrote: > >> Hi, Bernie. >> >> How is this better/different from RFC 1751? >> >> Thanks >> >> Yoav >> >>> On 23 Feb 2018, at 12:42, Bernie Hoeneisen <bernie@ietf.hoeneisen.ch> wrote: >>> >>> Please be informed that another I-D of the pEp (Pretty Easy Privacy) series has just been published. You can find it on: >>> >>> https://datatracker.ietf.org/doc/draft-birk-pep-trustwords/ >>> >>> Abstract: >>> >>> In public-key cryptography comparing the public keys' fingerprints of >>> the communication partners involved is vital to ensure that there is >>> no man-in-the-middle (MITM) attack on the communication channel. >>> Fingerprints normally consist of a chain of hexadecimal chars. >>> However, comparing hexadecimal strings is often impractical for >>> regular users and prone to misunderstandings. >>> >>> To mitigate these challenges, this memo proposes the comparision of >>> trustwords as opposed to hexadecimal strings. Trustwords are common >>> words in a natural language (e.g., English) to which the hexidecimal >>> strings are mapped to. This makes the verification process more >>> natural. >>> >>> Anyways, we are looking forward to your feedback! >>> >>> All the best >>> Bernie >>> >>> >>> ---------- Forwarded message ---------- >>> From: <internet-drafts@ietf.org> >>> Date: Thu, Feb 22, 2018 at 9:17 AM >>> Subject: I-D Action: draft-birk-pep-trustwords-00.txt >>> To: i-d-announce@ietf.org >>> >>> >>> >>> A New Internet-Draft is available from the on-line Internet-Drafts >>> directories. >>> >>> >>> Title : pretty Easy privacy (pEp): Trustwords concept >>> Authors : Volker Birk >>> Hernani Marques >>> Bernie Hoeneisen >>> Filename : draft-birk-pep-trustwords-00.txt >>> Pages : 6 >>> Date : 2018-02-22 >>> >>> Abstract: >>> In public-key cryptography comparing the public keys' fingerprints of >>> the communication partners involved is vital to ensure that there is >>> no man-in-the-middle (MITM) attack on the communication channel. >>> Fingerprints normally consist of a chain of hexadecimal chars. >>> However, comparing hexadecimal strings is often impractical for >>> regular users and prone to misunderstandings. >>> >>> To mitigate these challenges, this memo proposes the comparision of >>> trustwords as opposed to hexadecimal strings. Trustwords are common >>> words in a natural language (e.g., English) to which the hexidecimal >>> strings are mapped to. This makes the verification process more >>> natural. >>> >>> >>> The IETF datatracker status page for this draft is: >>> https://datatracker.ietf.org/doc/draft-birk-pep-trustwords/ >>> >>> There are also htmlized versions available at: >>> https://tools.ietf.org/html/draft-birk-pep-trustwords-00 >>> https://datatracker.ietf.org/doc/html/draft-birk-pep-trustwords-00 >>> >>> >>> Please note that it may take a couple of minutes from the time of submission >>> until the htmlized version and diff are available at tools.ietf.org. >>> >>> Internet-Drafts are also available by anonymous FTP at: >>> ftp://ftp.ietf.org/internet-drafts/ >>> >>> _______________________________________________ >>> I-D-Announce mailing list >>> I-D-Announce@ietf.org >>> https://www.ietf.org/mailman/listinfo/i-d-announce >>> Internet-Draft directories: http://www.ietf.org/shadow.html >>> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt >>> _______________________________________________ >>> saag mailing list >>> saag@ietf.org >>> https://www.ietf.org/mailman/listinfo/saag >> >>
- [saag] I-D Action: draft-birk-pep-trustwords-00.t… Bernie Hoeneisen
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Yoav Nir
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Bernie Hoeneisen
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Salz, Rich
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Yoav Nir
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Michael Richardson
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Andrew Sullivan
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Hernâni Marques (p≡p foundation)
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Volker Birk
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Hernâni Marques (p≡p foundation)
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Bernie Hoeneisen
- Re: [saag] I-D Action: draft-birk-pep-trustwords-… Michael Richardson