[TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt
Rob Sayre <sayrer@gmail.com> Mon, 17 March 2025 18:44 UTC
Return-Path: <sayrer@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 297A6D2CA30 for <tls@mail2.ietf.org>; Mon, 17 Mar 2025 11:44:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gpFND2ox3M-0 for <tls@mail2.ietf.org>; Mon, 17 Mar 2025 11:44:48 -0700 (PDT)
Received: from mail-pj1-x102e.google.com (mail-pj1-x102e.google.com [IPv6:2607:f8b0:4864:20::102e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 96C97D2CA20 for <tls@ietf.org>; Mon, 17 Mar 2025 11:44:48 -0700 (PDT)
Received: by mail-pj1-x102e.google.com with SMTP id 98e67ed59e1d1-2ff69365e1dso2858422a91.3 for <tls@ietf.org>; Mon, 17 Mar 2025 11:44:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1742237088; x=1742841888; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=hjzkTLYERMWDhwbkAK5aroh0LebqnIbXUIkhWriZm4o=; b=TdIRagkInqXsNFYzf/HglXZuethkulwcHSqAErf18yHu9k+EDIS0LvZCO384UbU7ZI 0qCDFlmzMIYDZaph1j1P2jpCjaQkbK0UZkCYmMtYd8PCwtgiVEKkeSUNHSPDLBMWd2ET UqN72Ux1Fqz2j8DQ/2+OXGpV+8ENcVCPcqUlX22WpFe6tLua+Y3VVhnmXRPWrgArFsLn qDo1kwJYozKxoRrG3+N9bXyHZbN65cw2vrrUSws2fW424Il/CQC3lfmjwPUhzIo/RmFn XaOm20+/wpSJfy5xNq8sG29H2OcEKj4uzsKeuM/fK/yhGmKx+rLY2pS68UF8NlAh4CHd TDDQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1742237088; x=1742841888; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=hjzkTLYERMWDhwbkAK5aroh0LebqnIbXUIkhWriZm4o=; b=Qj+Wqszae4xuF2qpIywPgqp4UCBkCaOJe1UEFzyD+p9vHaDcpjxLIInq6pptg2b81Y BoSwdjY4mykTqo5lbxWuP1TfRdcbxJqR0mXP5k0yzLED+DiQtl8YG9rXICdsKtF5FB8I 3hRQ9xQa7YSt4a9wqPp/ZHWCPn+xpVbjg3GV8o2IpktH9tt+NjkScHwvMgRyxTy+9dsI wybdsJgrGDMb4UJg7ecLO9beq25LyP9yxUyXhIv6bQpK4cEtZ0/ako1lz9dnhn+KEcsX 9OT1kzSbO3qG2jGtUa40H7dNNeE62YS5NBbl366K67Ik4rM8y6xsZbsmcSBszNtak0jw BW0w==
X-Forwarded-Encrypted: i=1; AJvYcCUiLqyCnpeinQ2VcjQyVz2K6/A0D3ohDvZwBJT9bcg0TXQBSd8bvcc51gJtPB4es9foRKs=@ietf.org
X-Gm-Message-State: AOJu0Yyio0u9tjHAAROuOq+THuUEKZpXQRCg1sjOrHggBlB09fkm/bsu inO1skjWw39kV2zoChlrTHMUb80UPIF2yaZ2V3MhzyPI7Sx05STtAkWjItKo2vS2hxJXGefsEHR 5wKVlF5AIZxLZzx/nZrpa3m6h4kc=
X-Gm-Gg: ASbGncuuC5XCsV2XPfi0J3Exg04QjmiTU8IL21hcenvq6pQQQxK/Ve+N80VNH0vSJGm 0ZX945dgC4UMT3U6wnjl10rZb71OKU2hrhfoCt+TBibZDmtlrW33mQqFmAqhsAG7Q2JwVrpZCMw 7egmYVl/HBAMrkRXuv6ZdXpNIRlmU=
X-Google-Smtp-Source: AGHT+IEqMaod9c+vXH2FbMfl4NfTrO9pqBIKun6o88ru4KyUM9n/o6MND743UeNg7jAW0Kb6draU4ehwSJjvYQn6xwg=
X-Received: by 2002:a17:90a:e7c3:b0:301:1d9f:4ba2 with SMTP id 98e67ed59e1d1-30151daa260mr16459004a91.28.1742237087572; Mon, 17 Mar 2025 11:44:47 -0700 (PDT)
MIME-Version: 1.0
References: <05B28816-9AA9-4035-B451-8ACFFBE2D4DE@apple.com> <CAChr6Sy1Eew1J5z9at3qEwLRWn+7ZLm0f564LobNQGMD7ANQaA@mail.gmail.com> <CABcZeBOpk2cYAyie4=G5=c6V43HvGB70fKVf_e_bQqnt_4C9WQ@mail.gmail.com> <CAF8qwaAoYEZj_t56unUAqz+SaKw6CvMFJ2NmqNmE8skmjKKSpA@mail.gmail.com> <CAChr6Sw+9bZxjcaJMNbY8UZBbmv5ZDnyb7aGtCjXcrtxvfeoew@mail.gmail.com> <CABcZeBNFPLWcYDhv1axqSwTX_w_yatfbJyih8CUMhZfkK5484g@mail.gmail.com> <CAChr6Syji7TKs6GumtmpZ8_tKXb5UK10_b6HdR1PU8Oni0pTkw@mail.gmail.com> <CABcZeBOHSGBOj_4R0bVdCpaRTcVV6=uHOzvWcY9HFei7PbC1fw@mail.gmail.com> <CAChr6SxFNN4wH=45HANWuFZVX8_2HfX14mS2WayVSe_ide2RWg@mail.gmail.com>
In-Reply-To: <CAChr6SxFNN4wH=45HANWuFZVX8_2HfX14mS2WayVSe_ide2RWg@mail.gmail.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Mon, 17 Mar 2025 11:44:36 -0700
X-Gm-Features: AQ5f1Jp6hLdxPURliaBAQWJ-I-_3mAoyUfHW-SuzyIYL0b52b2qOPj3zVFowx4g
Message-ID: <CAChr6Szz2HS71x2DnekY3Os4LaNEJs704rgSjRhVL9z_VF43jg@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Content-Type: multipart/alternative; boundary="000000000000b82c6306308e2e2b"
Message-ID-Hash: JQJRRIR46NK2OXMMLDL7WTGIAU34W26T
X-Message-ID-Hash: JQJRRIR46NK2OXMMLDL7WTGIAU34W26T
X-MailFrom: sayrer@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Laura Bauman <l_bauman=40apple.com@dmarc.ietf.org>, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/vlwizFuqMp_AXykc1sf4eeh56qs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Mon, Mar 17, 2025 at 10:02 AM Rob Sayre <sayrer@gmail.com> wrote: > On Mon, Mar 17, 2025 at 9:38 AM Eric Rescorla <ekr@rtfm.com> wrote: > >> >> As above, I don't see what this has to do with PAKEs at all. If you have >> a third >> party authentication system, whether sign in with Apple, Google, or some >> SSO >> provider, then you don't need to share any secret with the relying party. >> > > In my mind, the idea is that you don't have to rely solely on WebPKI if > you have that information handy after registration. > The other PAKE draft on the agenda explains this motivation better in its introduction, although the mechanism is different: https://www.ietf.org/archive/id/draft-guo-pake-pha-tls-01.html#name-introduction In draft-bmw-tls-pake13-01, the words "such as" are doing a lot of work in the abstract and introduction. I doubt they are aiming at passwords that a user types, given all of their other efforts to ditch passwords, but idk. thanks, Rob
- [TLS] Feedback on draft-bmw-tls-pake13-01.txt Laura Bauman
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt David Benjamin
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Björn Haase
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Laura Bauman
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Rob Sayre
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Christopher Patton
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Christopher Patton
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Martin Thomson
- [TLS] Re: Feedback on draft-bmw-tls-pake13-01.txt Eric Rescorla