Re: [TLS] TLSrenego - possibilities, suggestion for SSLv3

Michael D'Errico <mike-list@pobox.com> Thu, 12 November 2009 00:34 UTC

Return-Path: <mike-list@pobox.com>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 96E0F3A694E for <tls@core3.amsl.com>; Wed, 11 Nov 2009 16:34:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.573
X-Spam-Level:
X-Spam-Status: No, score=-2.573 tagged_above=-999 required=5 tests=[AWL=0.026, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N5TtxQ8PwbZx for <tls@core3.amsl.com>; Wed, 11 Nov 2009 16:34:10 -0800 (PST)
Received: from sasl.smtp.pobox.com (a-pb-sasl-sd.pobox.com [64.74.157.62]) by core3.amsl.com (Postfix) with ESMTP id 989733A69CA for <tls@ietf.org>; Wed, 11 Nov 2009 16:34:10 -0800 (PST)
Received: from sasl.smtp.pobox.com (unknown [127.0.0.1]) by a-pb-sasl-sd.pobox.com (Postfix) with ESMTP id C5CAA9B27C for <tls@ietf.org>; Wed, 11 Nov 2009 19:34:38 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=pobox.com; h=message-id :date:from:mime-version:to:subject:references:in-reply-to :content-type:content-transfer-encoding; s=sasl; bh=unu7QExLF18w +eJPHpvOTX/9kQE=; b=XOS7u10FXp3eYq1rRoVBWbCSsiANGVNspdh7THyn0Hog qCBbItnh+KwfCULl2eWhJDX5e1Y/Ob3BwOBeu/Ddf5DRCr8DN/u5CLEkISFcM0JH 20Kem+T/3hIR7YmrL5nL2uqn3xhNESEzdKBdTf3FzB4dNBC0yg+9XidxpzdlpWA=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=pobox.com; h=message-id:date :from:mime-version:to:subject:references:in-reply-to :content-type:content-transfer-encoding; q=dns; s=sasl; b=b0iiba PZx+cMS7sFSEBljE3mNiaP/k9nedax1/Ll1lMacFg+FZ4qqcUJGJ/kWdgEUYZ9TC TN5FyUKGBEhsCEvAWmo6YNVWLpCaL72nGUhCWXZAoNsHCoTOplsjYK+2EPS1wf58 MmUYCisN4WRbUuMpPXxt2daoBF6dBJZIR+AgE=
Received: from a-pb-sasl-sd.pobox.com (unknown [127.0.0.1]) by a-pb-sasl-sd.pobox.com (Postfix) with ESMTP id C1F009B27B for <tls@ietf.org>; Wed, 11 Nov 2009 19:34:38 -0500 (EST)
Received: from administrators-macbook-pro.local (unknown [24.234.114.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by a-pb-sasl-sd.pobox.com (Postfix) with ESMTPSA id 77AC99B27A for <tls@ietf.org>; Wed, 11 Nov 2009 19:34:38 -0500 (EST)
Message-ID: <4AFB584D.5080205@pobox.com>
Date: Wed, 11 Nov 2009 16:35:25 -0800
From: Michael D'Errico <mike-list@pobox.com>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
MIME-Version: 1.0
To: tls@ietf.org
References: <200911111916.nABJGtVm015003@fs4113.wdf.sap.corp> <4AFB21E8.7040609@extendedsubset.com>
In-Reply-To: <4AFB21E8.7040609@extendedsubset.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Pobox-Relay-ID: 291190F8-CF23-11DE-8B62-EF34BBB5EC2E-38729857!a-pb-sasl-sd.pobox.com
Subject: Re: [TLS] TLSrenego - possibilities, suggestion for SSLv3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Nov 2009 00:34:11 -0000

>> A client that is performing an initial handshake does _not_ know
>> whether there is a security problem, therefore I'm very reluctant
>> to suggest clients to warn users when performing a traditional
>> initial handshake.
> 
> The client can determine if he is handshaking with an unpatched TLS
> server when he sees the Server Hello message without the RI extension.
> It sounds reasonable to me that the client might indicate this
> potentially-insecure situation in whatever UI or log facility the client
> application provides.

A MITM could remove the extension from the ServerHello to trick you into
thinking the server doesn't support it.  Unless you finish the handshake,
you won't know.  But if you do finish it, you could be attacked.  Very
insidious!

Mike