Re: [TLS] Static DH timing attack

Achim Kraus <achimkraus@gmx.net> Thu, 10 September 2020 13:36 UTC

Return-Path: <achimkraus@gmx.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 013763A0A2B for <tls@ietfa.amsl.com>; Thu, 10 Sep 2020 06:36:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.048
X-Spam-Level:
X-Spam-Status: No, score=-3.048 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.948, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=gmx.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OLTTrjzZl99R for <tls@ietfa.amsl.com>; Thu, 10 Sep 2020 06:36:18 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C9303A0A21 for <tls@ietf.org>; Thu, 10 Sep 2020 06:36:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1599744970; bh=IQ5EOZw5VVZ6KV5m9Po2ftFfRiXaUiKODuq6FlUWg8w=; h=X-UI-Sender-Class:Subject:To:References:From:Date:In-Reply-To; b=Q77SNUOY0JCJCOGmj5+NxClp+v2dQxMPUwW/22LjfH6iznt9F4s7n/cwZy6tDYp7o cm1GhwIkRawNAkt3dXbeArqs9a8UY34kb+x+aODzny67Agvfg5YGUw0azZrSDx3Pfn zbqI1TsRaWuSg+UHceNTSQsuBZxqEMKhQOfXcJuw=
X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c
Received: from [192.168.178.45] ([88.64.91.252]) by mail.gmx.com (mrgmx105 [212.227.17.168]) with ESMTPSA (Nemesis) id 1MrQEx-1kuuRJ1lbD-00oUVQ; Thu, 10 Sep 2020 15:36:10 +0200
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>, "tls@ietf.org" <tls@ietf.org>
References: <5595BB40-3AFD-4327-B7B7-5E63FFC594DD@akamai.com> <1599729784370.87441@cs.auckland.ac.nz>
From: Achim Kraus <achimkraus@gmx.net>
Message-ID: <fff1a66a-0a49-cfbd-461a-c1d0ed3aeaaa@gmx.net>
Date: Thu, 10 Sep 2020 15:36:08 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0
MIME-Version: 1.0
In-Reply-To: <1599729784370.87441@cs.auckland.ac.nz>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
X-Provags-ID: V03:K1:VsT7PK3MIPPsE4q+sSq36awrd2JfkA9Z70KtHUJ9mITtxNN0pr/ 6T6+rrIQ5ARllTOpr65kZwgPj2vidX1f3vIp95KX4wZq+ASbKwLgrBewfYAsxqtqO9+yHe4 0beD1FcfL0+2SrOZZ0+zMvMFDcNTSdWW7pvsHA+BiInncRHaGYBfceBn2WHIogSpfX6lv93 OVvz5P5retsxEu301+cUg==
X-UI-Out-Filterresults: notjunk:1;V03:K0:NQpFX7TyOv4=:w97m3VmVzdmMgt9KC6c1C7 rlmUQdNvA+wGd0eaUgaVkcpAPQA+Q3E9PRJRiQp5xT2v4sAwMOHPxP777b+5A/5PQwwlpXsHo ER+cEWVC9EQGp6zYPm6vD8+KGt0+KP5m+IpbW9OwH6C8Zp3FpBVtitEvekxR0q1/8yAwXyW/P Skcy8n5l8VhnWY4TY3cjDQAMhNJfDwOiCUlcOtwuHOrYH1+Vz8c8cx8Y9FYxggCYIOgXRZgWz n8tjUQOF8dzPW+Ut9wjxIXMWaybiNUwqbHnkprbRT2T2qKeULHG40KXR6CO6gAM7GQZqfl66P 4nLFIVR0EHPSdf2Uygxg/wpKmWGxBqC44NDRhi14H4lBQ3dDeyjTesz1R/pRRTZkkg7SWgx/X szZUZUUK03hVqruNFiMEJDITWMncnrtr3IRhINqvj63GsJXjR1nnYrUbMl9+rmm1YvG9/lbeQ eC4KP8rW+mQuP1se0aks1oVvDspkq18eUQOvQUJ7pHoQTMbWk5nd37Osajo5Q4OK9kjA0gKzh trhn4ylnwR+XJRchSzKCJguLwZY1j/4k+vAvJJhXq9VhV7gOCW9QAg3FQZR8aOhD0B3lSQY9e kE9XeGh+Bbx/J4bRrVKJ2J2xVneegGsb08IdtqeO5XGr6CfmASw1jJqkM8wTHR/Xotp9hE3jz BecWTHYHle+U/Mttzsgl+F5zhJI5aoLX4iBxA7p4sQC5vCe1SO3cf7/JplM69Dmca3aEXEC1q +AMn9B2O9UU8Q2dVT70EW+Eax/NpijhatR7Ayrvzzpf/hxeSsgsNh4/jbhXgtaCcOmBqMmuub efQIdBlZX7ftsKOMUGvFmD3WMxkQnWPJ15xEik2vyatGpVRK97V1snkALrtRZ5aqAdzoXlQBI /L5ZWgQr+0hqy9lZ/ALAVflHRyJc7OM5o+BTsYS/Qu22PEG0N4m0EQf54B7wyvdI+4/LZq3+H mXN8oeveos4kjGoXhq7ZPso632G+0Zcuxa26YJovf0dJ8eFwXck39uHr6oDJhK6Y5XZOJZ+mc cjCzRFaW11FIN7c0ceuyU6Jql9qOOyHyE2/em00RBVjyS4N8Nxs3YP748WQXADHyZal58EpBS TilmgvAlTOY5IZIG9H4kgbzMeuPcAU30WU7r/1u35U9FuSDSf9bs1YFOGMmAld7v3qViG7w5q /BQ9AF3OuABSU3qIUF3ZOMhnhycQSsNB/7zgIxMKG44CyapgOiAVDZaHoatlUoXrWsru09mj+ MdceIsCJafm2Chx3XGfTPznGkSpEmweWTW+xZzg==
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/3eyxUs3dUIfkhpHzPiGwPlppmhA>
Subject: Re: [TLS] Static DH timing attack
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Sep 2020 13:36:19 -0000

Am 10.09.20 um 11:23 schrieb Peter Gutmann:
>
> Reason the second: Telling people not to use static-ephemeral DH will mean
> telling them not to use 25519 key exchange, which will make their heads
> asplode.
>
> Peter.

So, risking damaged heads:
Does using x25519 for ECDHE is significant less secure
than using it with e.g. secp384r1?

Or do I mix-up things and "DH with 25519 keys" is something different?

best regards
Achim Kraus