Re: [TLS] Deprecating more (DSA?)

Alyssa Rowan <akr@akr.io> Thu, 17 April 2014 08:13 UTC

Return-Path: <akr@akr.io>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3D43D1A00FD for <tls@ietfa.amsl.com>; Thu, 17 Apr 2014 01:13:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5VmG-pp-kwNk for <tls@ietfa.amsl.com>; Thu, 17 Apr 2014 01:13:48 -0700 (PDT)
Received: from entima.net (entima.net [78.129.143.175]) by ietfa.amsl.com (Postfix) with ESMTP id 72D641A00F9 for <tls@ietf.org>; Thu, 17 Apr 2014 01:13:48 -0700 (PDT)
User-Agent: K-9 Mail for Android
In-Reply-To: <C26BBD5C-C990-43B3-9466-9224897D2AD6@cisco.com>
References: <CABcZeBOvxL7Zws0UNowViBWGaVBgfm3zXt8=dNPKffGfN3q2gA@mail.gmail.com> <20140415153435.7f82b3a0@hboeck.de> <534F05DD.5010906@akr.io> <C26BBD5C-C990-43B3-9466-9224897D2AD6@cisco.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="UTF-8"
From: Alyssa Rowan <akr@akr.io>
Date: Thu, 17 Apr 2014 09:13:33 +0100
To: tls@ietf.org
Message-ID: <9c61cc29-1f0d-4bd9-970c-3ee811004ee7@email.android.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/tpMGc9SJLloHVZ2PQcPG3ZucXTc
Subject: Re: [TLS] Deprecating more (DSA?)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Apr 2014 08:13:50 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

I don't have much time today, but really briefly, to cover this point:

On 17 April 2014 00:33:52 BST, "Joseph Salowey (jsalowey)" <jsalowey@cisco.com> wrote:

>> [akr] • DH_anon?
>>   - Subject to thoughts about possible opportunistic encryption,
>>     although this definitely isn't the way you _want_ to do that.
>>
> [Joe]  Why not?

Here's (very briefly) why not:

• Alice: "I'm fine with RSA, ECDSA or DH_anon…"
• Mallory: . o O ( A-ha! Alice is probably being opportunistic and won't catch me! )
• "Bob" (Mallory): "What a coincidence, I'm fine with DH_anon too! :D"
• /mitm'd. :(

- --
/akr
-----BEGIN PGP SIGNATURE-----
Version: APG v1.1.1

iQI3BAEBCgAhBQJTT40tGhxBbHlzc2EgUm93YW4gPGFrckBha3IuaW8+AAoJEOyE
jtkWi2t6j8wQAJqOm4H4Yt6BizKWEU8slkRaEAuD9r0fmlJr8y5wSASHu+TIfk8Y
c6BECOBUx8Sk4gUjvZr0wMUJyeJ/F06EmzII9BxwUMrJ4FZBu1R3Dx+Nkiolwr6R
fdQK7zDBgRtJhbJs5NFJ8nQEawQeMeMhMb5npOCxQffkS41Vt/watUyfZUYPkui9
Ve/4OFAxKQx08GgMg61XZ0DzYW2IHGNI/5wgVJdkMUILt9Ep/mztYToNoh11uo8k
XaN2JhTIOY22KsuftqxgDmEeA6gR4rD0ZadcayK2ujWWZgBSEjGGyXnS/Nz3zHc+
WnJfmTuQX79IVy6vyJnT5wAdK1giAAwB35eIOjfohNR2jNePbefzA2WMQiPBLnVT
3Ix314IBgg5b8wGj5nwN1ZuIL214YnrJkufAWhWhQ9+QJPGOE2UH8OdORp2H9nkc
A681ZgOF7NsFVIldWaurkvi5nx3AiSQ+2e3OuXKH37xx1ZYn2Qm7dF+WXCWCKLVL
UEJimdHxl/kO2EYkMaqpFsO2JsatZpPTXCCvDGtFvDC4p4xrjdKJKyG1n1uMo5kb
PGv8uw/SMoBAm/Vb5J5seqvib9ls0IjdMhajhTpxa/qJFnXxsl1nO/BgiGaooU/l
R/GflgA3pxsjlg0QDKWzJrDihmtpAimwoaCBVIQNut5zLgweh/4M1eVJ
=j4Gg
-----END PGP SIGNATURE-----