[TLS] Re: TLS 1.3, Raw Public Keys, and Misbinding Attacks
Peter Gutmann <pgut001@cs.auckland.ac.nz> Tue, 19 November 2024 09:02 UTC
Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E05FBC16940D for <tls@ietfa.amsl.com>; Tue, 19 Nov 2024 01:02:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.006
X-Spam-Level:
X-Spam-Status: No, score=-2.006 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.auckland.ac.nz
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eiiC5d8ofFLd for <tls@ietfa.amsl.com>; Tue, 19 Nov 2024 01:02:44 -0800 (PST)
Received: from AUS01-SY4-obe.outbound.protection.outlook.com (mail-sy4aus01on2167.outbound.protection.outlook.com [40.107.107.167]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 12744C1E643C for <tls@ietf.org>; Tue, 19 Nov 2024 01:02:40 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ta7k8V2ifpl+OCechFJf56RpHJhQyeJPxEzf8mUNYDO9lpEWuEmnnPaaaJPoW4fP4Q4u6t8sKly2YWQnrAIkCaBifiNWoiscKNQg3J32FFq4JxYNS9DIh5SY6x7AGkNCernnGUL0GGNPdj8s9wslKihNkl6pB0J/WIE5wE+IZYZO8SoKYfIDFCR8ZJex+pw8Aa46BMxj5LRyPbVO5C6wmUzSfkPa9WSjpe1tC2WM+wCXiO/5AaYhfIXqLW4wDWUyCqpZuqLLvsmP0hFlcaicJsErba8oLdOgPmopiEKQ94eM4/r9dJCasP4Vge1QhjtXjMBxPeTSA7Z6pgHJbz651w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Vpm/TIRWbBYg0hKRhX7bs0lajJ+Em3fndZQLqXQQ+qo=; b=c6pQK+7MVZsoaJaaCJqvszr3NLZ1BhNVEs4EtSyNUi6nQT4G8HGmD1eUBUxFGBJ/YIGW8c6SphjMht+0oaRP6xkmetH22J98P0OncFtTkTFWXQmYO1idMcdDLF1wQT+FnvEKLTDv4iSTk66lstV8zoAvJrfSCdqJAjE5rJMvpaatlhK9NczLq4ZvDAN02HxqUPmj9MVZccOf0FtY24WqJM5YGH3FcB9XiMii7+aqMddX7uoJ9VuSk/Cah0LM/6pOlP09gbTe63BoJFnvvmR+/whR3Y8zVFV0EPMu6XOT/GkYrDJ6VV1bHcCJJjD5+nVcGoEkknPmlJHJsG5z49C5Zg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.auckland.ac.nz; dmarc=pass action=none header.from=cs.auckland.ac.nz; dkim=pass header.d=cs.auckland.ac.nz; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.auckland.ac.nz; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Vpm/TIRWbBYg0hKRhX7bs0lajJ+Em3fndZQLqXQQ+qo=; b=nm8XdZyJrY475UXV1wgMbUxa5r61w5cKRxCrz3ymURHFZP/77XZn9l9z8E3WkcGh5mc62XAzRCJsb+gDBhC7hLgHKHsR+YB+6uD9IwC4EdjV1K5wqBe7xKdr3dhAKZMmH1RJf1laAwgjV8oCbyeu/R4wXT38ZIwEaCMydH9XbasKoJTzPCI6y/dfB1f2J7dAu8bgc/P2PxarFwBVNxO5Ju+/Z3r8qkPhIjbMLlqX1Miq2mrYFd3fLXiwvJmDRbtfLSG5ooW+LJiuyd/Dcf6rRFsjZrszlYT5tln35++4JGyeSUvBuTEkkCG0Z/o/Pn5YaJVh/Un5IcCZZYiOCLO2Vg==
Received: from SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM (2603:10c6:10:295::14) by SY7P300MB0505.AUSP300.PROD.OUTLOOK.COM (2603:10c6:10:290::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8158.24; Tue, 19 Nov 2024 09:02:37 +0000
Received: from SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM ([fe80::92f2:d152:ed85:d49f]) by SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM ([fe80::92f2:d152:ed85:d49f%5]) with mapi id 15.20.8158.023; Tue, 19 Nov 2024 09:02:37 +0000
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Achim Kraus <achimkraus=40gmx.net@dmarc.ietf.org>, Mohit Sethi <mohit@iki.fi>
Thread-Topic: [TLS] Re: TLS 1.3, Raw Public Keys, and Misbinding Attacks
Thread-Index: AQHagSJ9IianpISz5U22vf2RrMlNorFqvBhAgVNG4QCAAAiUAIABkUKAgAAV9YCAAAw17g==
Date: Tue, 19 Nov 2024 09:02:37 +0000
Message-ID: <SY8P300MB07111A5F1ED7AAB62C32036BEE202@SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM>
References: <GVXPR07MB9678DFD1EED3971606FB3DE6893B2@GVXPR07MB9678.eurprd07.prod.outlook.com> <AS8PR10MB7427BE068D9472C465A7392EEE082@AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM> <5a79de00-2204-4e92-84bb-8b9b272a6ea6@iki.fi> <6aff1943-e896-4b00-8a61-d00c3b574953@gmx.net> <b986a11a-c00a-43a5-80d0-100dbd3f6fbf@iki.fi> <c5fe3a26-e3f7-458a-8ced-8915c5e45b3d@gmx.net>
In-Reply-To: <c5fe3a26-e3f7-458a-8ced-8915c5e45b3d@gmx.net>
Accept-Language: en-NZ, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.auckland.ac.nz;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SY8P300MB0711:EE_|SY7P300MB0505:EE_
x-ms-office365-filtering-correlation-id: a3c56714-79fe-42a0-39c2-08dd0878ea06
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|38070700018;
x-microsoft-antispam-message-info: 8IaEmPJ1N5GhpJDZjgd61lJhoJkuQ36UkK3/iCdjIwjZCT5NBrqBIXNxk2lWMuBP0/emz1WJBywWcUSrvVPph/PixlOA7IA8XDM2vOempOIOFXm9aoqeENqGS2JQTInChdizVlgAzf1EQ53GBfG4cUs3VHKFJs87WlI36h3HrSGS26LBo7RkTKoMSyP9a4/TvNrMVCPTMbYvt7+MaURuWTPzv7UA8YeJ9TNH6Ur+3K2VdkW5H7O3I6bUQfHsbrsnoG+JLRVwzPt2Di7D8YcDCx6H6LojIb4a6MBUy+6ViemnOkklYatjRYkN7ZeaTgy+c4Ii06nxFUHOX8xAnrhW+ElDb015n63yOsAH1CjLFrDjhEIl0mQx9YTpXKhK3mV+Gt7RmmzhK7Hc48gKia5NcgsMG8o34WhdhXiHyI9ISxp+s8FRlSsj2Osg3jAe0N30QtgpUJ/n5AolbbV0ztkVnyVFi+6UxOy/OKISog53A5gdhRRwTtgtUCvtUVzlYnkAo0/V74QJJRfeeZSU/oaX6BnVgHblhF5kQcj29Ba+Jj2RKzDaQqNfMdTqVo1k+R8/LZ8gAHWg70u9cvAYzEpic0z0ucfHEAQZvfux4DqvkrnYG+iL0gxPfKB+Voz2Z7YmBwK6tyoO35j8Z/1oXiPQle8inmyHNdMl0z0KsL6L2fBpo44bUT//CUN5ydKYVkFA7m4iiTEGrimItlE3NFEAYPlpfW1mI1OeQs3rEL07qwzTBeecr+wEx1P5p8G0XDzHFpv1MfAk9a74ZHuhawc3FSgstyuKxuf8c6G6BlZPtpiVGHvnPAIrDQ9XhxU/kWj5KxI6N4jAbrXhSHYRmyXuIu80bQF7ucEfwGTg1ynTFgd+Haa5EHfsDHm2GNqXZoMbnOKq3uJ0cwFKEM89ZPZb4kgr10kWBFcobIWF5kUCPZI8eDF0KOHZIv4c3eHYlTXUwoG6IQ1tTZ7XxyFRme1mkT2hqR06HavERADe21vvVNaPv6xDUNG7tmdX31Veo74isO/sZ8ZMumG5xfLl4svmPkx+HPmeLmdVZFYuqZ0FJjQELz5IZ3ITeltkkqWZfTBccWlaJ4DFJyqNfrFqZMUPMeg3dRw2cvBtPDjdI1kuZdvV8/awgMr6gXgWwBm1fWA3Ov1O2u3NPSsM6d0IMdXZsfunylq1DaP4TNVqWbord2eV8T/v5oaV8iWgnP7o9Gn0tQG0Ae1PJ2zjUmISao3aggL4Ij4LBp8YSykqkanYq4KrcmGtgvgktQ1BVUogFmXw1JfjcHLntYsCF3tt+CE9sLhf87FuCbPgB3TkFsDz9GtNfZW3Y31EnBzIU6hrsAAV3u2yZXlhUnX403qOmLPmXW5IrQqJi3+Bj5dR2nG6zqY=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(38070700018);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: iETEQsGsLmYdousxOiNzYvITLKSRc9wu60Ygx0OtKy7U4gZgr9RaJsOWmjUMXITj4MkCOJYMjqPx8aD23PJ/cfdmSL0lOpRjWqbBrhhxhga9KJarYIehsvUkGxorbOXP4RZZTKJW3+FPkqPh9NA+Q7JyffoSIHXcYm1ov4BSetZM6vp+dJAr4+sT7/Q9ZG9LCjdlbOtQSvQ1934etaAF7QwMy73uKYVxTajAl4Fg6UD+TodVBI3X7a5YfAKl53DYtz0Xy1KVj7EwsaY44YmSGS4rjYDNP5Dktp6a8yzUdW9Y558HaxLIUVSk9H8/G7Ge/o5jCTQ7eKHVPhqJCS8gseEvF/WQipRm0b6WM1DGaPjz6+K8p29HE9xDmvkqf5a/jTJ2jP5CDkZ/aRcfqHghZzJSQbinx8p8/e83mwKUSm7uXqWLYKv4/Uwn654PNkwkX4jq86k1mtIKWX8mkysSrHUkK/aUoInLKlTa6ImVMF6j2FcstO5EpOEop3vW5sRUslGetVoDa+TmoO1Sf8YDAoM2a3XOlQKF/y362ClhSzQFSIMn2fPpSPYTWGxk6uDglWOOdLc+E4ZJ8O/NOw9QTwrwA3wuVLw/+1T4iLHGL/wmDP3AR2b3w7riUnDo7SnqHyEPGI5wtt7cgRbIPq8bwbBYViRGqFuK5HTbcQs+VYLP3oAD3LJxbq4FwXYN7wNAZJmtNFRJvUe4F0aaVHy2BKi4bRmYGvzVTFKaaypEf2sbACTus0LcqvKNfj3qT9s9nNUsIzBSjwG81iQq5bMVz9dL9hKVrbNUbQQr2dh5fCHGX3kWbXbp/B1Ep3XInWfBVJ7HrRLhaaWfwNhBQa7vjRJ0QmZ6LpBhwkFLajXLHtIWE169vIKFhXEn5NNSo1F8+VXegfbQq+f1fhw+xbQWRkny/ffG8uRdCn6Yg1rNrsK5E/TLLdj0Ka5r3W+gE/zEhGREyiWDbFnHozYt+RhGi/MMBhGiK9chEzl7b4d1ZPhEzRPfNJhXXJRf9xqf7lnxLgXI99o+MTjiNMJTnOus14pWx006m16htLDXLbIIkl57tht66d4rR12Z32M6QQmMPKFXQeVFqohWYcLSXPu6PsENXREtJrHfqZFLr+O2SWWj0KK4eCdY7p6oAe8FCwUzD1/tGbszdfrXB5zhHf9p6ibwftS+YMaGlRjL5MSpJvjyTKL+N3Zl+TWj+w7KR4JQVXv73kx8oLJQI7EU0yYiwEdfBBS6kZ4z/4eM4cwuW1y5HE3NLfivRzNfONyVjmjP/6sFESitplyx419DoE5/lU4KA/ftwfgEDJpJBdfaqqSZcD6G4gPk191vvFp44LgTsopfCerFjlZZCwtL4E+2IanOsFq/Xjnfif1onLu7Bg5DsDCDEnm/GSwBxhEqyjQdlYw588FMUOF+jYI/RIc5JOlJFEiqcirkKY9YSoQvyxil3eRgtEtDdYfnRNr1rcWJroRfzfzDJV9RILUWPI4iTcCpEzn5z8G1+3LpJG0MNszTXfWNZ9XLL170Ue/aoDQthk30khCkVu4DcH51eApTwK068fcTcLhAAFxBUVhweu977GGyKf5usvniq6qrvj/m
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: cs.auckland.ac.nz
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SY8P300MB0711.AUSP300.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: a3c56714-79fe-42a0-39c2-08dd0878ea06
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Nov 2024 09:02:37.1580 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: FlNye+So6BOvi+C4RFhwQ/Tlr/luqbYnLWB7kvsmRSEhGDHmX/ylWYrJC2j4qNoC7JrKBB0sfSBchT5MV8PV6B/6GItf31CT5cdxQgF1+wk=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SY7P300MB0505
Message-ID-Hash: 6QTB6MJH36NRF2IPMMUX5ZVUCNE2IJL2
X-Message-ID-Hash: 6QTB6MJH36NRF2IPMMUX5ZVUCNE2IJL2
X-MailFrom: pgut001@cs.auckland.ac.nz
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "Tschofenig, Hannes" <hannes.tschofenig=40siemens.com@dmarc.ietf.org>, John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: TLS 1.3, Raw Public Keys, and Misbinding Attacks
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/CcAwO_CX4xu7XH0eGSz5bYjUOQk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Achim Kraus <achimkraus=40gmx.net@dmarc.ietf.org> writes: >> B and C are fighter jets, and A is their commander. B has been >> compromised by the enemy. A tells B to self-destruct, but because B >> mounted a misbinding attack, the command goes to C. > >As long as: >[...] But more importantly you also need to have: - Fighter jets in combat use TLS to communicate. - The other side has compromised one or more of your military aircraft. - Your military aircraft have a self-destruct command controlled remotely via TLS rather than the pilot saying "Begin auto-destruct sequence, authorization Picard 4-7 Alpha Tango". Peter.
- Re: [TLS] TLS 1.3, Raw Public Keys, and Misbindin… Dennis Jackson
- Re: [TLS] TLS 1.3, Raw Public Keys, and Misbindin… Bas Westerbaan
- [TLS] TLS 1.3, Raw Public Keys, and Misbinding At… John Mattsson
- Re: [TLS] TLS 1.3, Raw Public Keys, and Misbindin… Viktor Dukhovni
- Re: [TLS] TLS 1.3, Raw Public Keys, and Misbindin… Martin Thomson
- Re: [TLS] TLS 1.3, Raw Public Keys, and Misbindin… Tschofenig, Hannes
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Mohit Sethi
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Achim Kraus
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Viktor Dukhovni
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Ilari Liusvaara
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Mohit Sethi
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Viktor Dukhovni
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Achim Kraus
- [TLS] Re: TLS 1.3, Raw Public Keys, and Misbindin… Peter Gutmann