Re: [TLS] ChaCha and IVs

"Salz, Rich" <rsalz@akamai.com> Tue, 04 March 2014 23:11 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF80E1A006A for <tls@ietfa.amsl.com>; Tue, 4 Mar 2014 15:11:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.747
X-Spam-Level:
X-Spam-Status: No, score=-4.747 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.547] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LxGNWg6rqBdZ for <tls@ietfa.amsl.com>; Tue, 4 Mar 2014 15:11:40 -0800 (PST)
Received: from prod-mail-xrelay02.akamai.com (prod-mail-xrelay02.akamai.com [72.246.2.14]) by ietfa.amsl.com (Postfix) with ESMTP id 206931A0076 for <tls@ietf.org>; Tue, 4 Mar 2014 15:11:39 -0800 (PST)
Received: from prod-mail-xrelay02.akamai.com (localhost [127.0.0.1]) by postfix.imss70 (Postfix) with ESMTP id 477CC28563; Tue, 4 Mar 2014 23:11:36 +0000 (GMT)
Received: from prod-mail-relay02.akamai.com (prod-mail-relay02.akamai.com [172.17.50.21]) by prod-mail-xrelay02.akamai.com (Postfix) with ESMTP id 3404228509; Tue, 4 Mar 2014 23:11:36 +0000 (GMT)
Received: from usma1ex-cashub.kendall.corp.akamai.com (usma1ex-cashub5.kendall.corp.akamai.com [172.27.105.21]) by prod-mail-relay02.akamai.com (Postfix) with ESMTP id 29BE4FE2B4; Tue, 4 Mar 2014 23:11:36 +0000 (GMT)
Received: from USMBX1.msg.corp.akamai.com ([172.27.107.26]) by USMA1EX-CASHUB5.kendall.corp.akamai.com ([172.27.105.21]) with mapi; Tue, 4 Mar 2014 18:11:35 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Adam Langley <agl@google.com>, Dr Stephen Henson <lists@drh-consultancy.co.uk>
Date: Tue, 04 Mar 2014 18:11:34 -0500
Thread-Topic: [TLS] ChaCha and IVs
Thread-Index: Ac8324e8+dt+fX0+Riy9ZrEIJde2bAAIxE4A
Message-ID: <2A0EFB9C05D0164E98F19BB0AF3708C711EFC395B0@USMBX1.msg.corp.akamai.com>
References: <53160513.20703@bbn.com> <1393955839.20861.20.camel@dhcp-2-127.brq.redhat.com> <53161BA7.3070405@drh-consultancy.co.uk> <CAL9PXLzMiq-WsaAO8Q=kWqbQ3taw-xtuNw_ffuZxjFUXCEEG9A@mail.gmail.com>
In-Reply-To: <CAL9PXLzMiq-WsaAO8Q=kWqbQ3taw-xtuNw_ffuZxjFUXCEEG9A@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/MCNLs6tglQdVIH011abgcLwq2Uw
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] ChaCha and IVs
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 04 Mar 2014 23:11:42 -0000

> I'm unwilling to have the whole world waste bandwidth, and have a more dangerous specification, because of a bureaucratic problem.

For eight bytes.  Shrug, okay, your battle (if, in fact, it is; Wan-Teh could be rightr).

Nothing prevents TLS from saying the nonce should be the record number.  Careful implementations could compare them.

Your company may not care about FIPS, but many TLS users/providers do.

	/r$

--  
Principal Security Engineer
Akamai Technology
Cambridge, MA