Re: [TLS] [Cfrg] Salsa20 stream cipher in TLS

Adam Langley <agl@google.com> Thu, 21 March 2013 12:18 UTC

Return-Path: <agl@google.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63AF021F8FB3 for <tls@ietfa.amsl.com>; Thu, 21 Mar 2013 05:18:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.978
X-Spam-Level:
X-Spam-Status: No, score=-101.978 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q4uduRC9Qrnq for <tls@ietfa.amsl.com>; Thu, 21 Mar 2013 05:18:12 -0700 (PDT)
Received: from mail-ia0-x22c.google.com (mail-ia0-x22c.google.com [IPv6:2607:f8b0:4001:c02::22c]) by ietfa.amsl.com (Postfix) with ESMTP id E4F6921F8D68 for <tls@ietf.org>; Thu, 21 Mar 2013 05:18:11 -0700 (PDT)
Received: by mail-ia0-f172.google.com with SMTP id l29so2381791iag.3 for <tls@ietf.org>; Thu, 21 Mar 2013 05:18:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type:content-transfer-encoding; bh=MypFymk4QieoA1rH9jqvXhuymNOmPE3yWiImN1Mjec8=; b=Jg4N29Uf+NZhxRLt/mUqQBDCAoPCy3oI4fQhcJn3i3IeUDB5hRV9ioLnBBx1mOff1m 3JQnPYBlJouD07Wcdbz6lGTWaLWXlGvghbOg1sZwYcUIKg1BI7c5FeaWRqEvb8i0UA8s RgBMbPflKq5u2eqSs8ExjDNscSRWYdJB2K7D0pKuPf3eSzSr8sEiNWmVDST60Dg0bY1g tDsLIOvu6Hn5jcOCAoDg+WaN9idmW6Xnfh2j0vxqL4Qrjx58ECF/w6MHZxO2EXH+vVpA lhb/rCQMeBHp65b/l8DDOy69C1OJqVpph7vFLYGiePzM9Ok3/QJvtkT5KdjnYdCxiwkH V7QQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type:content-transfer-encoding :x-gm-message-state; bh=MypFymk4QieoA1rH9jqvXhuymNOmPE3yWiImN1Mjec8=; b=a/E3NWjCDjn+klyZ54Wv4iSY/b9pe5IAra+t1fzumEHcekxmXsn/hB4bSHv0KyooyP V5VhP+IjBUKWToyBDkyuslErxUk65GkfZRaNqpA3lV2Lq9XRXy2vWD+SmOqVc2vcFM0/ yK/MhW5Nz76rvODNmkuzEHMmpfDaIADRMbLfiT8wfAV5lOONqUvjmTw3K8ASoEiGEAbF NEcC3cNqTP2/T5L9gGNYXgddogyJveYKD+PZeyYHRMJ2mZSPLrSa1cjzUOy7I2tloGX0 16Qud30C5y0mGlnaFS0TZtJLGJcGaYKTVmVpYhps9+l0QcG0Cz+3iVl2R1/TQSwABGcw q98Q==
MIME-Version: 1.0
X-Received: by 10.42.145.137 with SMTP id f9mr15924512icv.52.1363868291429; Thu, 21 Mar 2013 05:18:11 -0700 (PDT)
Received: by 10.231.229.135 with HTTP; Thu, 21 Mar 2013 05:18:11 -0700 (PDT)
In-Reply-To: <B41639CC-CD95-4188-8843-B0DDAA298A01@checkpoint.com>
References: <9A043F3CF02CD34C8E74AC1594475C7343D245C7@uxcn10-2.UoA.auckland.ac.nz> <B41639CC-CD95-4188-8843-B0DDAA298A01@checkpoint.com>
Date: Thu, 21 Mar 2013 08:18:11 -0400
Message-ID: <CAL9PXLxs82DeXPOAK4SbsEsrKXUi-26p-LyNZB2GkeLNwbqxVg@mail.gmail.com>
From: Adam Langley <agl@google.com>
To: Yoav Nir <ynir@checkpoint.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQmv4Oub4kbWw+dnO2sV78+2GfRc+3ZZT73dyjBd9yM51Tvk3nJ8PufYT3fuzM4bAw2uUkE+ciCamPhztN++u9xcsQ5yUYnxR+QW2vmSJHsoH4YM9kIsMYPciwHaCGBe6gYqmhqb9B/4tF73I7CKaxhMkKSnojiH8V2pS+qaR5OhXMks5G24shad+K4QZQc875I9hV8u
Cc: "cfrg@irtf.org" <cfrg@irtf.org>, "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] [Cfrg] Salsa20 stream cipher in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Mar 2013 12:18:12 -0000

On Thu, Mar 21, 2013 at 8:09 AM, Yoav Nir <ynir@checkpoint.com> wrote:
> Actually, we turned on TLS 1.2 by default for the speed advantage. iOS begins a TLS handshake with version 1.2, both in ClientHello and in the record layer. Only when the (shocked and flabbergasted) server closes the connection, does the iPhone try with something more sane like 1.0, and then even caches this for a short while.

But you don't need to switch on TLS 1.2 to fix this, right? The server
just needs to implement version negotiation correctly.

(On the flip side, this /is/ a problem for clients since the
incentives are aligned for clients to stop trying TLS 1.2 since they
can't (directly) fix the server.)


Cheers

AGL