Re: [TLS] padding bug

"Lewis, Nick" <> Wed, 25 September 2013 08:33 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id E4FE321F9F34 for <>; Wed, 25 Sep 2013 01:33:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -0.997
X-Spam-Status: No, score=-0.997 tagged_above=-999 required=5 tests=[BAYES_50=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, UNPARSEABLE_RELAY=0.001]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id rXVUdDcWgohC for <>; Wed, 25 Sep 2013 01:33:07 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id E9A9E21F9FAE for <>; Wed, 25 Sep 2013 01:33:01 -0700 (PDT)
Received: from [] by id 4B/B5-04812-BBF92425; Wed, 25 Sep 2013 08:32:59 +0000
X-Originating-IP: []
X-StarScan-Version: 6.9.12; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 29244 invoked from network); 25 Sep 2013 08:32:58 -0000
Received: from (HELO gbtwk10s037.Technology.local) ( by with RC4-SHA encrypted SMTP; 25 Sep 2013 08:32:58 -0000
Received: from GBTWK10E001.Technology.local ([]) by gbtwk10s037.Technology.local ([]) with mapi; Wed, 25 Sep 2013 09:32:57 +0100
From: "Lewis, Nick" <>
To: "''" <>
Date: Wed, 25 Sep 2013 09:32:57 +0100
Thread-Topic: Re: padding bug
Thread-Index: Ac65ydZhkjFJWjbPSvuJeogMKfJ34Q==
Message-ID: <AAE0766F5AF36B46BAB7E0EFB927320630E4A54283@GBTWK10E001.Technology.local>
Accept-Language: en-US
Content-Language: en-US
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_AAE0766F5AF36B46BAB7E0EFB927320630E4A54283GBTWK10E001Te_"
MIME-Version: 1.0
Subject: Re: [TLS] padding bug
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 25 Sep 2013 08:33:12 -0000

Martin Rex wrote:
> Where I agree is that it would be preferable to limit any fix to the exact
> problem that has been identified (already by Vaudenay), which is in how
> SSLv3&TLS use a Blockcipher in CBC mode with "authenticate-pad-encrypt"
> rather than "pad-authenticate-encrypt".

I agree that the fix should be limited to the exact problem. The fix could be a change from AtPtE to PtAtE
using a greatly simplified version of  without
the length hiding features


The details of this company are as follows:
G4S Technology Limited, Registered Office: Challenge House, International Drive, Tewkesbury, Gloucestershire GL20 8UQ, Registered in England No. 2382338.

This communication may contain information which is confidential, personal and/or privileged.

It is for the exclusive use of the intended recipient(s).
If you are not the intended recipient(s), please note that any distribution, forwarding, copying or use of this communication or the information in it is strictly prohibited.

Any personal views expressed in this e-mail are those of the individual sender and the company does not endorse or accept responsibility for them.

Prior to taking any action based upon this e-mail message, you should seek appropriate confirmation of its authenticity.

This e-mail has been scanned for all viruses by MessageLabs.