[TLS] Re: Comment on draft-bmw-tls-pake13

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Thu, 29 May 2025 18:21 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E9E922E6B9E3 for <tls@mail2.ietf.org>; Thu, 29 May 2025 11:21:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -11.886
X-Spam-Level:
X-Spam-Status: No, score=-11.886 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cisco.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cSoNh8SzkhU9 for <tls@mail2.ietf.org>; Thu, 29 May 2025 11:21:50 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A21212E6B9D5 for <tls@ietf.org>; Thu, 29 May 2025 11:21:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=22308; q=dns/txt; s=iport01; t=1748542910; x=1749752510; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=eGqpC8o1flDkNfNLZRq++xdblaulK7YXE0E2X5kt1Cs=; b=Kw+fKhCl8b9AiEqzvGkFh+p9TumVW3BDW9xOr6SAKZixgPfa4UqLAphl +wOtKfFzdmKzQNI7zCfB0HC6ddkKpLNy5OtR6VFSXnLdUdhOznXLT7lqT RwTAPqsITlJzsIGtKGp0TSxFc6OT3reZBdaUes+w8wdBcVod2gevX+XfD xzijY+XbiU/HEiMuN5a8CPb5sY+WU1y+/p8xxIu+1sSFZ2o6xmR9tn/FB wrAjd6b33oDdlhhsqSGp54inetfK44jl2kgVXHgs0B5cqJXmH7bC7zyeR go6Sx8Cl1ljEujrGu1zkUghtdsDE9RTusD9DiHK6rliGVmZlqpg2JBd8Y A==;
X-CSE-ConnectionGUID: MTDi+101R3KsSS+xHFHAHQ==
X-CSE-MsgGUID: VKOXHD2US7u4huOyC+HmSQ==
X-IPAS-Result: A0AFAACTpDho/4wQJK1aGgEBAQEBAQEBAQEDAQEBARIBAQEBAgIBAQEBZYEaBQEBAQELAYFAMSooBzg9AoEcSYRUg0wDhE1fiHYDl0E8gTtahAQUgREDVg8BAQENAjcaBAEBhQcCFos/AiY0CQ4BAgQBAQEBAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4V7DYZaAQEBAQMSESsgBAcQAgEIEQQBARkPAwICAi4BFAkIAQEECAYFCBUEAYJhghwGAQEBAQo8AwGlcAGBQAKKK3qBMoEB4B4GgUkBiE8BKoEzAg6DfgGCRIE4eycbgUlEgRVCghVTPoJhBIEpARIBCRoGDx8agws6gi8EggkbWigKChILD4U6hAhwgX4CAQSBBDY3EINOFYJ2Uy4DQHIEaoc1UnIiAyYzLAFVExcLBwWBIEMDgQ8jSwUtHYINhRkfgXOBXAMDFhCEAhyEYoRJK0+DJIF+ZUGDXxUMCCFAAwttPTcUGwUEgTUFlkUHCgtAhFVTIFsiKCVCBi2Sb4QHi1aiM4E+CoQbjB2VaxepemaZA4oJg36VX4UnAgQCBAUCEAEBBoFoPGlwcBU7gmdSGQ+PVQECh1zFJngCOgIHAQoBAQMJkD2BVwEB
IronPort-PHdr: A9a23:/PfPDRzJ8uEEAJbXCzPsngc9DxPP853uNQITr50/hK0LLuKo/o/pO wrU4vA+xFPKXICO8/tfkKKWqKHvX2Uc/IyM+G4Pap1CVhIJyI0WkgUsDdTDCBjTJ//xZCt8F 8NHPGI=
IronPort-Data: A9a23:CloW4axpzjFvS2p+eG96t+dzxyrEfRIJ4+MujC+fZmUNrF6WrkUAn DRLUG/UOKmDYjbyLYtwbY++/RxVu8DcmNBhG1Nk+FhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCea/FH0a+KJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 I2aT/H3Ygf/hmYpaDNMsMpvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJGQKEYxbo74uOzpt7 scjayAtQDCqp9vjldpXSsE07igiBMDvOIVavjRryivUSK59B5vCWK7No9Rf2V/chOgXQq2YP JRfMGQpNUiYC/FMEg9/5JYWh+msm3nlfidwo1OOrq1x6G/WpOB0+OOyYYCOJ4XaHK25mG6mh UX230ijPypFKYCf1B2U2TGMg9T2yHaTtIU6UefQGuRRqEGX3UQSBQEYE1yhrpGEZlWWUtZbL QkQvyEpt6V3rBftRdjmVBr+q3mB1vIBZ+dt/yQBwFjl4oLf4h2SAS4PSTspVTDsnJZeqeACv rNRo+7UOA==
IronPort-HdrOrdr: A9a23:E0c4gKxfPAf5WReYpY3OKrPxbOgkLtp133Aq2lEZdPULSL36qy n+ppQmPEHP6Qr5AEtQ5+xoWJPtfZvdnaQFh7X5To3SLTUO2VHYY72KgrGSuQEIdxeOktK1kJ 0QDJSWa+eAQ2SS7/yKnTVQeuxIqLLogcLY4Ns2jU0dMT2CAJsQljuRfzzraXGeMzM2fabReq DsgfZvln6LQ1hSRMK9AXUOQujEoPP2tL+OW3Q7Li9iwjOjyRez5pDHMzXw5HojujV0rosKwC zgqUjU96+ju/a0xlv3zGnI9albn9Pn159qGNGMotJ9EEStti+YIKBaH5GStjE8p++irHwwls PXnhsmN8Nvr1vMY2COpwf30QWI6kds15ai8y7bvZLQm728eNsIMbsHuWufSGqe16MUhqA47E uM5RPBi3MYN2KZoM233am5a/gjrDvGnZNlq59Ts5SaOrFuMoO4auckjRho+JtsJlOJ1Kk3VO ZpF83S//BQbBeTaG3YpHBmxJi2Um00BQrueDlJhiW56UkfoJlC9TpS+OUP2nMbsJ4tQZhN4O rJdqxuibFVV8cTKaZwHv0IT8e7AnHEBUukChPfHX33UKUcf37doZ/+57s4oOmsZZwT1ZM33J DMSklRu2I+c1/nTceOwJpI+BbQR3jVZ0Wh9uhOo5xi/rHsTrviNiOODFgojsu7uv0aRtbWXv 6iUagmSsML7VGeb7qh8zeOLKW6c0NuJfH9kuxLL26zng==
X-Talos-CUID: 9a23:FJy3eGjtZ9KQT8Zssl12H+qQFDJuV0HxzTSJexaCUkVyc4bWWX++2IpEqp87
X-Talos-MUID: 9a23:6J2KDwmQTw0oLiLXd/drdnpcF+BYw4j0NXtSjMkGpu6VHm9QPgyk2WE=
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-l-core-03.cisco.com ([173.36.16.140]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 May 2025 18:21:49 +0000
Received: from rcdn-opgw-4.cisco.com (rcdn-opgw-4.cisco.com [72.163.7.165]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-03.cisco.com (Postfix) with ESMTPS id A4739180001D3 for <tls@ietf.org>; Thu, 29 May 2025 18:21:49 +0000 (GMT)
X-CSE-ConnectionGUID: /a3cJqUySGCUeYr3L11c9A==
X-CSE-MsgGUID: t882aMbCTueLxohHc7W37A==
Authentication-Results: rcdn-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.16,193,1744070400"; d="scan'208,217";a="53215556"
Received: from mail-dm3nam02lp2042.outbound.protection.outlook.com (HELO NAM02-DM3-obe.outbound.protection.outlook.com) ([104.47.56.42]) by rcdn-opgw-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 May 2025 18:21:49 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MnxAIF627nAhUXfVArMfduXy6MZjfFTkeACGzyxK6YmSTHNo9l6NS7NAwZu+nB3dVehRrtrV+CtCRuU3Zt8ThLWpZhqB8u0XRMzS3d46J02eX29pcqPePpW8zs/1v4CLLACNS+Q6dYPGdyCYZq/VTqleydtfEdMU8iQuT8dldIbLUFFyZJODP10BFdBbu6NI9mePmEIOeMW1ZcJw1PWQSVg0ywtZL5GrYLT2labs+czdkQxUEKgTPjAcT+uwcUoZRf7K7GMmDNzojuTH/WD+i7ZhDMCQ61VTQVWHcF/N/lsiZ/HmvGevWCFnRiHwOKQf0qUW5b8nfbH+SCC/QmLr1A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eGqpC8o1flDkNfNLZRq++xdblaulK7YXE0E2X5kt1Cs=; b=aaBHf0dWPqzBBHf7pDEmPva8fSjCkky6O9kMI8DrTVOXgV05ewkEJnDzj5tQsBmaSmU4CV3FGUVHgiYy9XoeYkS2Z6BNKmwwLtpJDJgdDwbUMJqvqIEmQjt3LMjfXBXl+Jx65kfMZlv/tHCcSTpPadOaf1u8azARNFtE9SRAokIan0/6GNxwis4YgH4sZrbDb1BU3tdyIhwRl04AvG/h8IkDpOFicFId+cjTBZ8NHiK4JXsTAb6S4Je0Ons6WM8F5dloeHlKTn6zxIHVRq0sznUPpHgVhLNX46vTwvLlX11YWsoyGllyUDtOIc6DzL0bc42IjvC9BU2J8Au3m3f1/A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from CYXPR11MB8709.namprd11.prod.outlook.com (2603:10b6:930:dd::21) by PH7PR11MB6356.namprd11.prod.outlook.com (2603:10b6:510:1fc::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8769.31; Thu, 29 May 2025 18:21:47 +0000
Received: from CYXPR11MB8709.namprd11.prod.outlook.com ([fe80::3336:dc75:81e6:58ef]) by CYXPR11MB8709.namprd11.prod.outlook.com ([fe80::3336:dc75:81e6:58ef%3]) with mapi id 15.20.8769.029; Thu, 29 May 2025 18:21:46 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Michael Rosenberg <mrosenberg=40cloudflare.com@dmarc.ietf.org>
Thread-Topic: [TLS] Comment on draft-bmw-tls-pake13
Thread-Index: AduUvDUKXWhlhggCRdOhyorMsz279A79v8aAAAIMh5A=
Date: Thu, 29 May 2025 18:21:46 +0000
Message-ID: <CYXPR11MB8709D199205F8BF00D8DD1B1C166A@CYXPR11MB8709.namprd11.prod.outlook.com>
References: <CH0PR11MB5444A5D0344C88ED3F93DB37C1D22@CH0PR11MB5444.namprd11.prod.outlook.com> <DA542CDD-F021-4C75-8170-47FE9FD2ED6C@cloudflare.com>
In-Reply-To: <DA542CDD-F021-4C75-8170-47FE9FD2ED6C@cloudflare.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CYXPR11MB8709:EE_|PH7PR11MB6356:EE_
x-ms-office365-filtering-correlation-id: 48c3273a-403f-472e-c496-08dd9eddabf5
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|1800799024|376014|366016|8096899003|38070700018;
x-microsoft-antispam-message-info: ULF8/lq8HZZDBEWpiuFEvo61dH+DP15tewrucru6EUQBQyYx/YpozZ4pxQzEHNUNrB9kXXZPv8Ers5ddoFP05sk7/7b8Yg7UoH1+bGnjRFdKNtGxLIBIBwDBTh9Z+edZxtaGsIs2GZ0mzuLEZbyuzQJ/YngSKZO8pHB0NQYRCBoGppiMXfY9dexB/b7oW7nhSwnIxEoOL3HgVJlPUV5nmOopJCYEqaqZcE6fjist0ctHVDzlLlZbpzqnGE8adyh2cBQDmoO5khORVu+nPKmJNmYf85RQUEUOkHn0MPNVrysQL+3lTeQHOKDaVYojfgFlqSO9Db1VnYvA/hzraT4nSYrRDTQ/9BkSfZJb9EOTZbXuiAZb6ArzlQ241WQ5LwU5Mpt/HL/BDI/PCKNnY5O6eI6fSSCMlOBLaIBNs1WpIshVSb0FrmvqDjI96a2jjZA25au+HEdADfCPNU1JsGDGiDZ9Zt6N+mamva+ycnAxIUe7KLhBT4uOAiOwofaV0vDYuOklcRlKdgLHgR8BpuQW0eNVG2R5gpIfH1BKERcE/8g25uVaONDM3CprpQvr9tfWhVDrbnCs3H6CHLI58V7FRukUfVZW9yZj1V7xqEEzn4+wI06xp+ENfv0WGRXmS+nacRmSDelOwEzUSgmCGTA2NGuUU2akxp89AyNIOd6bHGdILoPBL6lenVX896QYNOLDsuyWLv9LrfQTbOHhEpSVOGNj0gs7/DqgBxx5OY9WyXLJxtjL1HCbueeTyVx2tVBULC/IVdZQ0RWFu9dxOGTf2V2Vvvt6aQn0d7+WtUDa2zeYjHFvZucqrTJENankpkbPUnwTaPZdVnPYd5io8FMPEVblnXq+5dGuhR6aNGF5dnopIdFspPvNyAy4lG4syg0I8K4G4wYvOFRfrVwf3vL6004CUdCdhe7FuOTqH5m0sxiUikTopKXHzkwFvn2FYMfFWBEeEDw+URfkgP4yL3qrLOQt53StgwjpL5QSvRLNzkhPu8zO2gp+XXwJ7aqTIdVenHMT62Tl9jy/KS0NYCJVmv7wo+8XH00NLgY9GMMtD3uUKL7USpDmvH8dbA0SSKEwlW6Xppoga8CV0zod8IxbVcpE3UnuH3YbhaYYYvT4WLpvsgoQDItV/WRVwyhfVTejoMc2f1nRT2TeuCqoL3NnjIw3CPz7TWC+wloS7rRSTRZcT9fo1WgRNb6r+2BfpZ13YOMhgoF0H55F7+fyzrUBYNKQGQBCE7XGJMaQpTeWjjar3dMPH/Ir0c71q6f9yvY5sAXuUcb1claa8FonG+G0Uer+jEUDvom3t3tqm3d7P5nfM30A/182SDBnaT5g5f/qly52Ge5S33ioOWEKDMbwYJcgdy8e/YgOWDJThyh8r2+iNXcEap/ZuVTsISWarU3Ezbh347JEqSaYRmPIPfRO9UjoT8vpDTX85uT2SGDzKy4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CYXPR11MB8709.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(1800799024)(376014)(366016)(8096899003)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: otVwZgEmFTDV1gkXWqjuUnYE+0k7IKwKvtLv3dgXkR99xCXX2sX24AAlQjHPFyfpk4O+qFLPnpiA81fOizbZVOAHJgtqUaCvF94tLfLeylI1K0grSaDUHm2kT3bHroBQaZoOeQA6zA64vhktInCPN/I/z3trj9lLq4UrZtMH44bX/wvVc2YF/qlQmou+rywqsyRUwPWjFcX1Z2WD3e3TG3gtViMSpwW7rtCHv1RfFfbpQksQmWJEppbsdlmvrhb/Q9W5C8jXGpI4sHOwsYJ0BJIn8SleIZbJXNxZj4fxki/tYWhuePOMo0dZgjMXmQqwLFqhlYpJg6YF+5Jk4CF49zn/JPEBMhV7HCW7OnQc48/aUlze61lv4MtIgjGkzqAILysACszRl5/4gFrEU1JCxIHjsTNobBiMQJbFWC4pFe/e0RgRg+HqEQXAt/1oTIthrp0UGgf3jIg8n+R+GJA3sWARB9EmIlVn+EAVdLUU1nhbCe4n8jAaHGJOGq+NPlB6VV5juJhqXatEts1s1KvnpWxkIP6lDjldJyTAhO9cNYchEiYunONDFEW8CTfVO6sJYBp25nhdRPQpOjWz5Yz0UtrPiPbMgYZrZIlDm1i5tPjsVXPuUuBtjudkvg4Na+EHKZ9cbDuq2JOvYjfnn2c7ST16hL7uneMW+3aukufk47olZK44giOyl9SfaCJbuGqr7ekhCoLSVrT+b2IqkAwv1kkGzTvYXZ4uUx3mBGIsBCrcoz4p55GIe5vIbkPWtJSmAhLB62NzEOQJxV4R7QPanotBoL2ZzcEhLZNtXM8t7T3t83rxeo/9I6gXYgUvbAHPPj8Kl7CuJ8HDeoyftwREOppysh/bcYQEyHTtL/nTwU5pT9hMUL07PDxdo87e8a/SV8KsHWqOHF3M15EfL0D4UwZgeqdJHcrH2a2MRiZpKgyQX+enPN3S3fQ9AdSEab0u7GK0VkMwb2b4oHjYB+cVv/vIRlaDwnIr04suUWkPHOJnLh8YWsgQsA7T/oJrwUIDzSyovT1Sr6Rug+2uYwwP9MxiYyx+31NMLmDbUIUHqNEtrpTV6ayLaX1OjwvgeKL9tvzgGxYG7z4UQFJsvhaAJciVqWDxsErdPJQH4M3/9nkAV6wpayJegNojGzKKpHaILsXoEWxqY7/1jxjGNb8lHk3uo5T0fNsfM4DS2s+VxEi/pORHNidiWM06P2cXeF0aC1o4PYaXSF+cccwg07+pll2ce9UkS1RjpRe13vPR04tqsGoFATDyMcO0iSOvvRRKjaJ84jix4JJmiUVqTJqVgYo8AeW3z9ArydangSyP23BhUfqw/Xkqt6oLQZ8EkLr+OtL3Xold/iO3ynf5sWyfZOOY9eBPOjKdT4D35Pbs/vBHarr23dcVZGw1Bobl2ot8jCyG2yBIP/ddtlQF5oKjfJWOFanyK7TDDSKMLCVQAZ+t+16KuQTUPWDsQ1Pnt0SiEtuMz54kv7ppxX/RvDbYaFgHLus1tnMkYhmKWiZTDa4zVaRBWKZrYP62fGq/53agitCC2+Fu9NK5GHCSLescRpRphIMS025e7N95QIa8I58=
Content-Type: multipart/alternative; boundary="_000_CYXPR11MB8709D199205F8BF00D8DD1B1C166ACYXPR11MB8709namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CYXPR11MB8709.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 48c3273a-403f-472e-c496-08dd9eddabf5
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 May 2025 18:21:46.6123 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Eaqxj9rcN80ajbQya0AVbnS0FMUzogSwrrV2aahQoqWNkdV9CNDQJmjxoC9usZAfUAIvkDznBoLFc6n0SIcwZw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR11MB6356
X-Outbound-SMTP-Client: 72.163.7.165, rcdn-opgw-4.cisco.com
X-Outbound-Node: alln-l-core-03.cisco.com
Message-ID-Hash: 3DZSNP7NB5JBQHYDSVJQFDOTGANHCSVL
X-Message-ID-Hash: 3DZSNP7NB5JBQHYDSVJQFDOTGANHCSVL
X-MailFrom: sfluhrer@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "<tls@ietf.org>" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Comment on draft-bmw-tls-pake13
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/2QmaBycadf50LrUiz6HEr7WXoXU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Oops, thank you for pointing out my misstatement.  While there is a vulnerability with Spake2+, I misremembered the details (I must be getting old...)

The actual vulnerability is "if they know the relation between M and P, then there's an active attack and allows the attacker to test multiple keys as the result of a single exchange".

Here's how it works: the attacker controls the client and tries to log into a server (who knows the keys) (and in the TLS context, the client is the Spake2+ prover and the server is the Spake2+ verifier, and I'll be using the terminology from the Spake2+ RFC)

The attacker controlled client picks an arbitrary value r and sends the server X = r*P

The server then selects a random value y and sends back Y = y*P + w0*N

The server then computes:
Z = h*y*(X - w0*M)
V = h*y*L = h*y*w1*P

The server then computes the corresponding transcript TT and the corresponding  confirmV, which he sends.

Our attacker then breaks the connection and then, for each guess in his dictionary, computes the corresponding w0', w1'.  and computes:
Z' = h*(r - w0'*m) * (Y - w0' * N)
V' = h*w1' * (Y - w0' * N)
(where m is the known discrete log of M).

If his guess of the password is correct, then Z=Z' and V=V', and so the transcripts TT will match, and hence the so the computed confirmV will match what the server sent.  This means the attacker is able to scan through his entire dictionary, with doing only one active exchange.

This works because, if w0=w0' and w1=w1', we have:
Z' = h*(r - w0*m) * (Y - w0 * N) = h * (r - w0*m) * y * P = h * y * (X - w0*M) = Z
V' = h*w1 * (Y - w0 * N) = h * w1 * y * P = h * y * w1 * P = V

TT (and confirmV) is a function of Z, V and known data, so those can be computed.

Hence, while what I originally stated was incorrect, my point remains; by solving a single discrete log problem, the security guarantees of the Spake2+ (which is that a single active attack would be able to test a single password) becomes incorrect.

And, I cannot recommend endorsing a PAKE where solving a single discrete log problem breaks the system globally, given there are other PAKE protocols that do not have this vulnerability.

________________________________
From: Michael Rosenberg <mrosenberg=40cloudflare.com@dmarc.ietf.org>
Sent: Thursday, May 29, 2025 12:03 PM
To: Scott Fluhrer (sfluhrer) <sfluhrer@cisco.com>
Subject: Re: [TLS] Comment on draft-bmw-tls-pake13

Could you describe in more detail how finding relation between M and N leads to an attack? This paper<https://eprint.iacr.org/2019/1194> says that even in the most trivial relation, ie M = N, we have security under the gap squared DH assumption.

-Michael

On Mar 14, 2025, at 4:53 AM, Scott Fluhrer (sfluhrer) <sfluhrer=40cisco.com@dmarc.ietf.org> wrote:

I went through the PAKE draft on TLS 1.3, and while I certainly appreciate the use of a PAKE within TLS, I would like to highlight one potential security issue that the working group needs to be aware of.

The draft has SPAKE2+ as its sole defined parameter set; SPAKE2+ has a rather interesting property that if the attacker can perform a single discrete log problem, in particular, compute the discrete log of N to the base of M, that is, find k such that kM = N, then the PAKE properties go away.  That is, an active attacker can perform a single exchange, and then efficiently run through his dictionary of potential passwords and (as long as the correct password is in the dictionary) recover the password.

Let me repeat this: if someone can solve a single discrete log problem (for example, if he has a slow Cryptographically Relevant Quantum Computer), then the attacker can immediately attack any SPAKE2+ implementation using that parameter set, anywhere in the world.

If the working group endorses SPAKE2+, then they need to be aware of this, and should highlight it in the security considerations.
_______________________________________________
TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org>
To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>