Re: [TLS] Working Group Last Call for draft-ietf-tls-pwd

Trevor Perrin <trevp@trevp.net> Thu, 05 December 2013 22:16 UTC

Return-Path: <trevp@trevp.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B8981ADFB8 for <tls@ietfa.amsl.com>; Thu, 5 Dec 2013 14:16:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.208
X-Spam-Level:
X-Spam-Status: No, score=-1.208 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_SORBS_WEB=0.77] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TvZ2QTOQ9PLR for <tls@ietfa.amsl.com>; Thu, 5 Dec 2013 14:16:37 -0800 (PST)
Received: from mail-we0-f181.google.com (mail-we0-f181.google.com [74.125.82.181]) by ietfa.amsl.com (Postfix) with ESMTP id AFB6C1AC3DA for <tls@ietf.org>; Thu, 5 Dec 2013 14:16:36 -0800 (PST)
Received: by mail-we0-f181.google.com with SMTP id x55so17537181wes.12 for <tls@ietf.org>; Thu, 05 Dec 2013 14:16:32 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=axD0+aYruwQGX2Gy9KvB7uhvjIbmugtxvytezKdL2K0=; b=O2KyPFkZVyCw25gFvGpKzUKuVa+oLj1RsYvZr/nAgxyfWyzN6zXbjB4GabjVZ5/in1 Ivn11sEdZ6cG6MLyN0rIfXb2xRly6QDEVFz1tZ6Rv7Bg3YOSeHB6lehH5cEYE+w+w1FF /j5lyq2yEQPaeCnTZ4SE6gTkaGvaxrFAB96vBhmfGgxhyTyG2TfbNY/plNCgonj0/NsK OOikkcAsnWfYEYXWe90zZGxEWFnbqnOBIreiFX89jgKseVRxvFjThJlO1v7vcpI7Wjtr ZhOj25oQD1x+kSNCnygBOPQJg+Ouq96OCBuq5xavgj5Xb3nqDEhCGEfodJIn0RfGbVVR wWQg==
X-Gm-Message-State: ALoCoQkUu6V1T+lOH4W/nt48eGMXiUl8+QUS8pNFoLXO4C6wuxhu55aLutkk1U3JbRGrTf9e1cH6
MIME-Version: 1.0
X-Received: by 10.180.9.74 with SMTP id x10mr73893wia.56.1386281792791; Thu, 05 Dec 2013 14:16:32 -0800 (PST)
Received: by 10.216.214.134 with HTTP; Thu, 5 Dec 2013 14:16:32 -0800 (PST)
X-Originating-IP: [208.70.28.214]
In-Reply-To: <CAOhHAXyRa+we5G429thrwCVYx2OtGTAYK_24Zh-Rp4YVkMzd2A@mail.gmail.com>
References: <3065D910-832C-47B6-9E0B-2F8DCD2657D2@cisco.com> <529C990D.3020608@gmail.com> <CACsn0cmtP_dF7N2op4DZUwR8t-fW30GmtdqQoteZ+9Y0oH3dUg@mail.gmail.com> <a4b1729af4966e99df1582943f02a0a8.squirrel@www.trepanning.net> <CACsn0cksrU2GErd6FkZPkXKXK4pSJhTbBoJ-0C-14jsM=UY2iQ@mail.gmail.com> <14e67efee74d2ec6d535f6750ed829db.squirrel@www.trepanning.net> <CACsn0c=PnB2CA8rpNtcOp6RRLNWHEPN-aN+AdWSF7FJM2wZOog@mail.gmail.com> <6d86c3be1741ed14992ec8662e0d32c7.squirrel@www.trepanning.net> <CADMpkcKTAARYK2id27T44eVyx6gF24mkt9nAkUZbSmwtEtd2gg@mail.gmail.com> <6c129fd89a9e5953ba844e4e1d1e6e98.squirrel@www.trepanning.net> <CAGZ8ZG0n7AFWc_WpxLzKbhnRxz8hkQAD-j8VDtX_GOHD5Nc6nw@mail.gmail.com> <7c8448fa356f5d764186ca62552efb1d.squirrel@www.trepanning.net> <CAGZ8ZG3HwTe0gvrrieYAVZZSd=xfU9GWYo1YHMHWmD9c+EsxbQ@mail.gmail.com> <CAOhHAXyRa+we5G429thrwCVYx2OtGTAYK_24Zh-Rp4YVkMzd2A@mail.gmail.com>
Date: Thu, 5 Dec 2013 14:16:32 -0800
Message-ID: <CAGZ8ZG25H7p6V3iJGHpCixj5EDPfBkyeuaxULzUh8ch7vLdmrw@mail.gmail.com>
From: Trevor Perrin <trevp@trevp.net>
To: Mohamad Badra <mbadra@gmail.com>
Content-Type: text/plain; charset=ISO-8859-1
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-pwd
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Dec 2013 22:16:38 -0000

On Thu, Dec 5, 2013 at 1:30 PM, Mohamad Badra <mbadra@gmail.com> wrote:
> On Fri, Dec 6, 2013 at 12:42 AM, Trevor Perrin <trevp@trevp.net> wrote:
>>
>>
>> We should not standardize protocols which are inferior to existing
>> ones and to newer alternatives, have insufficient cryptographic
>> analysis, have no application,
>
>
>
> How was your document betterthan PWD when you initially submitted
> draft-taylor-tls-srp-00? The only security analysis was made by the authors
> of the paper on SRP.

I didn't submit the initial draft (David Taylor - 2001), nor invent
SRP (Tom Wu - 1998).

Regardless, that was a long time ago, when TLS had no PAKE, the patent
situation was trickier, SRP was state-of-the-art, and people wanted to
experiment with PAKE in the TLS handshake.

If the roles were reversed, and we were proposing TLS-SRP in 2013 when
Dragonfly had been adopted years earlier (and found to be largely
un-useful), we'd be met with the same skepticism.


Trevor