Re: [TLS] PSK in 1.3?
Sven Schäge <sven.schaege@rub.de> Thu, 19 February 2015 15:41 UTC
Return-Path: <sschaege@googlemail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 981941A90F6 for <tls@ietfa.amsl.com>; Thu, 19 Feb 2015 07:41:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.977
X-Spam-Level:
X-Spam-Status: No, score=-0.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fi-DF0g_81ef for <tls@ietfa.amsl.com>; Thu, 19 Feb 2015 07:41:15 -0800 (PST)
Received: from mail-ob0-x22d.google.com (mail-ob0-x22d.google.com [IPv6:2607:f8b0:4003:c01::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44A441A90EE for <tls@ietf.org>; Thu, 19 Feb 2015 07:41:15 -0800 (PST)
Received: by mail-ob0-f173.google.com with SMTP id uy5so15746876obc.4 for <tls@ietf.org>; Thu, 19 Feb 2015 07:41:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlemail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:content-type; bh=icG9//LkCqlDlSMgnfJnoFGPq0wQYgZftiaBceMwDbE=; b=vTmmt9jlZIj0NuZgdntsgjr4xX3Fd61BSq7aA+EbHwF8DY6RAqSO03D0+YdjPO5UPI EL4BWxuulEHminnFwqAYhqFTZ6QR0zCTMTpNFTHilJ/ZZX77wBF4oqbgCsN6el9nz4BC LHY+6Tbr8pt+thD22c7mkQXEhsyI+X3VTYbx79VlowendH55gN5gSrF2lZruxtMH/yEV nfofCeBMxUlT9/4AYaOkLMA3aA4jaIj5WQ+BxCCl2LYw2q44GT2dqg0yCNiI+eFpzYI9 VMCvF/8mBYPNrWGdoVENQpAm5kyXuoQU4M85BsK66GKC/dl/JE9T/hlFd+D/w86tnMRl 0bWw==
MIME-Version: 1.0
X-Received: by 10.60.58.137 with SMTP id r9mr3321210oeq.1.1424360474612; Thu, 19 Feb 2015 07:41:14 -0800 (PST)
Sender: sschaege@googlemail.com
Received: by 10.182.241.200 with HTTP; Thu, 19 Feb 2015 07:41:14 -0800 (PST)
In-Reply-To: <5e587b4474939cad09c12cbf3625dd98.squirrel@www.trepanning.net>
References: <544384C7.9030002@polarssl.org> <78795A6D-3DFA-41C6-A380-C63DDF4C0285@gmail.com> <5443BF11.3090505@polarssl.org> <1D875BD8-2727-4895-842A-FC4FAA482E15@gmail.com> <5e587b4474939cad09c12cbf3625dd98.squirrel@www.trepanning.net>
Date: Thu, 19 Feb 2015 16:41:14 +0100
X-Google-Sender-Auth: iuDNRBJ_K6oQvqpXyyW12j8P7cA
Message-ID: <CAO9bm2mQzjiLpMgB-mh-bRca-A2gkTZiBd9c3CsFq4kekBGxUw@mail.gmail.com>
From: Sven Schäge <sven.schaege@rub.de>
To: Dan Harkins <dharkins@lounge.org>, tls@ietf.org
Content-Type: multipart/alternative; boundary="089e0153729e1f1b12050f72c430"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/XCdHEX9h16uZEpqvg0JsY_5opJU>
Subject: Re: [TLS] PSK in 1.3?
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Feb 2015 15:48:51 -0000
I was just reading through the TLS-PSK related discussions so far and came across your post... 2014-10-20 14:13 GMT+02:00 Dan Harkins <dharkins@lounge.org>: > > On Sun, October 19, 2014 7:35 am, Yoav Nir wrote: > > > > I also understand that in practice, PSK ciphersuites are used only by > > small devices, whereas the web and SMTP and other things never went for > > it. But the standards don’t say that. They don’t say that PSK > > ciphersuites are especially for constrained devices. So if we insist that > > the same TLS 1.3 be used for both, and we don’t want to say that PSK is > > for weak security, then we should have a good story of why PFS is not > > needed for PSK uses, whereas it’s essential for all RSA uses. If I > > understand the mechanism correctly, PSKs tend to be long-lived, and a > > subsequent compromise of a PSK (even if it is expired at the time of > > compromise) allows an attacker to decrypt the content of a TLS session. > > The non-PFS PSK ciphersuites are no different than the widely > discredited, and easily cracked, WPA-PSK mode of WiFi security. It would > be a really bad idea to continue with these ciphersuites in TLS 1.3. But > the > issue is not just PFS (or the lack of it), it's that PSK ciphersuites are > susceptible to dictionary attack. > > > So either we believe that PSK compromise is unlikely, or we believe that > > the data in a connection with a PSK ciphersuite is not future-sensitive. > > If we don’t, we’re saying that we’re just piling on security > > nice-to-haves because we think the users can handle them. > > There's no way that the protocol can be defined to justify that belief. > What you're talking about is how people end up using the protocol and > that is entirely out of the power of this WG. What we can do is to make > TLS be as _misuse resistant_ as possible. And to do that we should not > allow PSKs in TLS 1.3 unless they are used in a PAKE. > > By the way, I'm surprised that no one is expressing outrageous outrage > at the lack of a security proof for PSK ciphersuites. > Perhaps you might find http://eprint.iacr.org/2014/037 useful. > regards, > > Dan. > > > _______________________________________________ > TLS mailing list > TLS@ietf.org > https://www.ietf.org/mailman/listinfo/tls > Many greetings, Sven
- Re: [TLS] PSK in 1.3? Yoav Nir
- [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Ilari Liusvaara
- Re: [TLS] PSK in 1.3? Eric Rescorla
- Re: [TLS] PSK in 1.3? Ilari Liusvaara
- Re: [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Yoav Nir
- Re: [TLS] PSK in 1.3? Hauke Mehrtens
- Re: [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Hauke Mehrtens
- Re: [TLS] PSK in 1.3? Watson Ladd
- Re: [TLS] PSK in 1.3? Jeffrey Walton
- Re: [TLS] PSK in 1.3? Paul Bakker
- Re: [TLS] PSK in 1.3? Eric Rescorla
- Re: [TLS] PSK in 1.3? Eric Rescorla
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Watson Ladd
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Watson Ladd
- Re: [TLS] PSK in 1.3? Peter Gutmann
- Re: [TLS] PSK in 1.3? Manuel Pégourié-Gonnard
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Mohamad Badra
- Re: [TLS] PSK in 1.3? Peter Gutmann
- Re: [TLS] PSK in 1.3? Peter Gutmann
- Re: [TLS] PSK in 1.3? Yoav Nir
- Re: [TLS] PSK in 1.3? Viktor Dukhovni
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Ilari Liusvaara
- Re: [TLS] PSK in 1.3? Sven Schäge
- Re: [TLS] PSK in 1.3? Christian Kahlo
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? John Mattsson
- Re: [TLS] PSK in 1.3? Alex Elsayed
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Viktor Dukhovni
- Re: [TLS] PSK in 1.3? Stephen Checkoway
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Stephen Checkoway
- Re: [TLS] PSK in 1.3? Dan Harkins
- Re: [TLS] PSK in 1.3? Stephen Checkoway
- Re: [TLS] PSK in 1.3? Viktor Dukhovni
- Re: [TLS] PSK in 1.3? Watson Ladd