Re: [saag] AD review of draft-iab-crypto-alg-agility-06

Nico Williams <nico@cryptonector.com> Wed, 26 August 2015 19:17 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A7C71A1BB4 for <saag@ietfa.amsl.com>; Wed, 26 Aug 2015 12:17:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.743
X-Spam-Level:
X-Spam-Status: No, score=-1.743 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_LOW=-0.7] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f0iMKyuLlsQc for <saag@ietfa.amsl.com>; Wed, 26 Aug 2015 12:17:42 -0700 (PDT)
Received: from homiemail-a28.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id B3D011A1B18 for <saag@ietf.org>; Wed, 26 Aug 2015 12:17:42 -0700 (PDT)
Received: from homiemail-a28.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a28.g.dreamhost.com (Postfix) with ESMTP id 1D0901B406F for <saag@ietf.org>; Wed, 26 Aug 2015 12:17:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:in-reply-to:references:date:message-id:subject:from :to:cc:content-type; s=cryptonector.com; bh=HJoy9jon2NZJPlJgCa9u 5mzc06s=; b=iyz5Ar7H3HYm2RU4C95NIqOFxVxmynTFqwcjTV/ZoStaUcjeqz6U XDguWy0sRKO1Eb/dWDl8rNX59JqnPDq+QDmkWALkD2VFze56rbrWG8yl/+otYz7o bEWfsTxDxTKp3Kg1cYnsdl38CcgUCcJ2eQRAwOgX4Brd+wgqpF0xkWc=
Received: from mail-yk0-f178.google.com (mail-yk0-f178.google.com [209.85.160.178]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a28.g.dreamhost.com (Postfix) with ESMTPSA id EBA871B406B for <saag@ietf.org>; Wed, 26 Aug 2015 12:17:41 -0700 (PDT)
Received: by ykbi184 with SMTP id i184so197334080ykb.2 for <saag@ietf.org>; Wed, 26 Aug 2015 12:17:39 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.170.44.23 with SMTP id 23mr58420ykm.52.1440616659893; Wed, 26 Aug 2015 12:17:39 -0700 (PDT)
Received: by 10.129.109.88 with HTTP; Wed, 26 Aug 2015 12:17:39 -0700 (PDT)
In-Reply-To: <55DD89F2.8050801@cs.tcd.ie>
References: <20150728053035.GR4347@mournblade.imrryr.org> <CAHbuEH7B3_G9vAhw=U2tuz-Uh8mKMUfL6s=H+BOG96FDZaACig@mail.gmail.com> <20150824212907.GN9021@mournblade.imrryr.org> <619ffebb05ba4e2a9af03a6dcc768d6e@ustx2ex-dag1mb2.msg.corp.akamai.com> <20150824215037.GO9021@mournblade.imrryr.org> <9A043F3CF02CD34C8E74AC1594475C73F4AE62A1@uxcn10-5.UoA.auckland.ac.nz> <20150825134333.GX9021@mournblade.imrryr.org> <6b5167f3d0684a8a91caa6d37dec65e3@ustx2ex-dag1mb2.msg.corp.akamai.com> <20150825160627.GH9021@mournblade.imrryr.org> <55DC961A.903@cs.tcd.ie> <20150826055240.GD13302@localhost> <55DD89F2.8050801@cs.tcd.ie>
Date: Wed, 26 Aug 2015 14:17:39 -0500
Message-ID: <CAK3OfOhkwAZ9bnNTj8EEpHeuwG0ou_5Fh=KfxCmu8Mt6jetKjQ@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Content-Type: multipart/alternative; boundary="001a11378e8e45466d051e3bb4d0"
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/ynvOcCRbRPJwzCabJPUxNVi1tFk>
Cc: "saag@ietf.org" <saag@ietf.org>
Subject: Re: [saag] AD review of draft-iab-crypto-alg-agility-06
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2015 19:17:43 -0000

On Wednesday, August 26, 2015, Stephen Farrell <stephen.farrell@cs.tcd.ie>
wrote:

>
> Hi Nico,
>
> On 26/08/15 06:52, Nico Williams wrote:
>
>
>
> I'm sorry but you're entirely ignoring the use of RC4 in the web


Not at all.  I'm arguing that rather than outright ban RC4 at the TLS layer
for all apps we should make it a SHOULD NOT use with guidance for various
applications.


> Another of the lessons of OS (or rather, of more seriously considering
> deployment realities) is that we sometimes need to think outside our
> own silos. That goes for mail folks and web folks and others too.
> (I'm not saying you're one or other of those, but your mail was very
> silo-specific.)
>

Exactly.