Re: [TLS] Working Group Last Call for draft-ietf-tls-pwd

Bodo Moeller <bmoeller@acm.org> Thu, 05 December 2013 20:56 UTC

Return-Path: <SRS0=loW3=VM=acm.org=bmoeller@srs.kundenserver.de>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA47C1ACCDF for <tls@ietfa.amsl.com>; Thu, 5 Dec 2013 12:56:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.93
X-Spam-Level:
X-Spam-Status: No, score=-0.93 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZTH54hk553NV for <tls@ietfa.amsl.com>; Thu, 5 Dec 2013 12:56:48 -0800 (PST)
Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.126.187]) by ietfa.amsl.com (Postfix) with ESMTP id B17A31ADFBB for <tls@ietf.org>; Thu, 5 Dec 2013 12:56:47 -0800 (PST)
Received: from mail-oa0-f42.google.com (mail-oa0-f42.google.com [209.85.219.42]) by mrelayeu.kundenserver.de (node=mrbap4) with ESMTP (Nemesis) id 0LqD3Y-1VJl0d2O12-00eNg8; Thu, 05 Dec 2013 21:56:43 +0100
Received: by mail-oa0-f42.google.com with SMTP id i4so19112663oah.15 for <tls@ietf.org>; Thu, 05 Dec 2013 12:56:42 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=6BjTP7Jfli4NwLFxFsAGnvsBpkupRHjLTCIXkZUdAgw=; b=Sl7vL5rA5zXoT4tRV9jYhXt3SomqI8t+cXwxXnjTfZbD24p4MSqDws0vrDsh0Jq48l RW8YX9LZdjQ6rX5SCnJmuj2vdQrcu1TIVbaQ6x5hGGi0XnUdihFKDeHlfMaJY8gqyfop jKnCl3TF+eG9xoZTao9iD7KlBqQw4TZt2o52yw31opIXk5qNo3ZB1Q+YS7pkVVgVjutx n17A6peTlDQ4XujdXqQudO4/c0CyFGZVc8MmlAI2O0wRJlws2tjhY8Z5sHfjBDEaAFQj r/exIRaifrMGya9HnAO0OpctW5Vx+yBDbDG9oD5fkM+w0BI5mgLcWcYZLJtuP2+uY2gc AZUg==
MIME-Version: 1.0
X-Received: by 10.60.44.193 with SMTP id g1mr16803814oem.47.1386277002307; Thu, 05 Dec 2013 12:56:42 -0800 (PST)
Received: by 10.60.137.194 with HTTP; Thu, 5 Dec 2013 12:56:42 -0800 (PST)
In-Reply-To: <6c129fd89a9e5953ba844e4e1d1e6e98.squirrel@www.trepanning.net>
References: <3065D910-832C-47B6-9E0B-2F8DCD2657D2@cisco.com> <529C990D.3020608@gmail.com> <CACsn0cmtP_dF7N2op4DZUwR8t-fW30GmtdqQoteZ+9Y0oH3dUg@mail.gmail.com> <a4b1729af4966e99df1582943f02a0a8.squirrel@www.trepanning.net> <CACsn0cksrU2GErd6FkZPkXKXK4pSJhTbBoJ-0C-14jsM=UY2iQ@mail.gmail.com> <14e67efee74d2ec6d535f6750ed829db.squirrel@www.trepanning.net> <CACsn0c=PnB2CA8rpNtcOp6RRLNWHEPN-aN+AdWSF7FJM2wZOog@mail.gmail.com> <6d86c3be1741ed14992ec8662e0d32c7.squirrel@www.trepanning.net> <CADMpkcKTAARYK2id27T44eVyx6gF24mkt9nAkUZbSmwtEtd2gg@mail.gmail.com> <6c129fd89a9e5953ba844e4e1d1e6e98.squirrel@www.trepanning.net>
Date: Thu, 05 Dec 2013 21:56:42 +0100
Message-ID: <CADMpkcJ09GPN=L8qeSAO+tQK40uO18N2R1dfkJU-9RQ=8R-9zg@mail.gmail.com>
From: Bodo Moeller <bmoeller@acm.org>
To: Dan Harkins <dharkins@lounge.org>
Content-Type: multipart/alternative; boundary="001a11333dc8486fdc04eccfc4e0"
X-Provags-ID: V02:K0:B/nKVdsBR8UA0hJ2V7xYckf4eTcUMGJ9BK+VBFiSoJ4 WYITEvfuq/a/+NcITFGFjJG6fektEQsXmxHTQjv92OcD5Uk3Yf x02hDv2D5EnkOR0mIDizNbwtecSZ0QdGGh6rtaxUDlcD9HhcuY BhH+SfxzOyCjR5CxdY3An+Nuaep8SsNOMqTsWLTKkypyerzaAY LIZK2ltVrHDRKRHlpMlIw5PXtI/5qZufDfaoQRO+v42nVuNVWB n3mrdQppLcbB0Kt8G0Ljg/6WdyMBjwhPTTLKLE5yNubor7qJsH 79yP8hPcOJOisx76F77dPQgx1dtRYpudHGeAA1McZIr28MChgg kyJdHwM4M8UJCE9PYcAG2Igp/bIoEE+CBx42dDiIBpfAIuDkso 1jV3+AldkFtXgsY6Sj41Z0LQ2scBq8+bx2vD2HZDiRvSMqansE g9//X
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-pwd
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Dec 2013 20:56:49 -0000

>
> > While it is true that Joe noted that, I think the point of the present
> > discussion is that the protocol wasn't actually reviewed by the CFRG with
> > satisfactory results.
>


>   No, that's not really true.  There is a difference between "your
> protocol has
> not been proven secure" and "your protocol has a security flaw". And while
> the former has been pointed out on this list and the CFRG list, the later
> has not.
>

Right, there's a difference between that (and good reasons to prefer
protocols that *have* been proven secure where those exist), but my main
point here was that there hasn't actually been a thorough protocol review
by the CFRG.

Bodo