Re: [TLS] Comments/Questions on draft-gutmann-tls-encrypt-then-mac-00.txt

Eric Rescorla <ekr@rtfm.com> Tue, 24 September 2013 20:11 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58BE021F9CE3 for <tls@ietfa.amsl.com>; Tue, 24 Sep 2013 13:11:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.976
X-Spam-Level:
X-Spam-Status: No, score=-102.976 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5Oj9AX4V4QjI for <tls@ietfa.amsl.com>; Tue, 24 Sep 2013 13:11:41 -0700 (PDT)
Received: from mail-qc0-f180.google.com (mail-qc0-f180.google.com [209.85.216.180]) by ietfa.amsl.com (Postfix) with ESMTP id 8E2B221F9928 for <tls@ietf.org>; Tue, 24 Sep 2013 13:11:41 -0700 (PDT)
Received: by mail-qc0-f180.google.com with SMTP id p19so3463991qcv.11 for <tls@ietf.org>; Tue, 24 Sep 2013 13:11:41 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:content-type; bh=VgJb/zJcyk0wDsJwETNjoJ3DdiQv0mwK3n0cvaI0YhQ=; b=Cnwv9AfY8Qe/4BCmqBMIqNTXhCMM3VnHFtM3wwNrm7LMWzUXzF26etBtDzsyOteAqY frZ90ghRs2nT4MpysEDEo0/8Do7UjJfmyFH7YUEpsXzbM7i96yPKD0VTNF9iMLHFQ0T2 OlVHxm1frld1e38u10T7EuniL5piqgu3h2m8f8lMAWwU+ABSSpDfHMmyKb4f0vVbPb3v M+b85tlx4MG5Ie/ZF8YYEaY9oCBk7Uqr5KPY3+yF7mfqbtuIzd9Y7cOBPKVn5890pqjw 42VItzFZzstQCMvnPlUS29xIMBYvpr0IdHrDvnHpuWmBXVrEoMr/snOexLqlgp7mNcWc NSNg==
X-Gm-Message-State: ALoCoQm47Q3YZiMU8EYWnLBISvVmzu9Lkt9OpPvYNpI8uOJu4hi63lcwjmJnpeFpkReBiEBicJsw
X-Received: by 10.229.219.199 with SMTP id hv7mr18657776qcb.15.1380053500934; Tue, 24 Sep 2013 13:11:40 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.49.42.68 with HTTP; Tue, 24 Sep 2013 13:11:00 -0700 (PDT)
X-Originating-IP: [141.212.109.200]
In-Reply-To: <CABcZeBN+0hX1-cb0V4AyaO3FrwaGrtjbRO3BGOV0KBSjRkNwkw@mail.gmail.com>
References: <CABcZeBN+0hX1-cb0V4AyaO3FrwaGrtjbRO3BGOV0KBSjRkNwkw@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Tue, 24 Sep 2013 13:11:00 -0700
Message-ID: <CABcZeBNaf3PMk=OFDUqLBVYSSzxGdyBsv4UVxhuK_BOaiAqAMg@mail.gmail.com>
To: "tls@ietf.org" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="001a11344874b1dae104e726bee9"
Subject: Re: [TLS] Comments/Questions on draft-gutmann-tls-encrypt-then-mac-00.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Sep 2013 20:11:46 -0000

Peter,

Do you think you could address the questions I asked below?

Thanks,
-Ekr



On Fri, Sep 20, 2013 at 8:52 AM, Eric Rescorla <ekr@rtfm.com> wrote:

> Peter,
>
> After reviewing this document I have a few comments/questions:
>
> - Because this draft relies on extensions, it seems not to resist
>   active attack when clients do insecure version fallback
>   (see for instance:
> http://www.ietf.org/mail-archive/web/tls/current/msg09468.html)
>   The existing attacks appear to principally be active attacks on the
> browser
>   environment, which is where fallback tends to happen.
>
> - Maybe I am misreading the draft, but I'm unclear on how you get
>    the TLSCompressed.length for the MAC computation in Section 3.
>    Does this have the same issue as was raised for McGrew's CBC AEAD
>    draft?
>
> Am I missing something here?
>
> Thanks,
> -Ekr
>
>