Re: [Unbearable] JWS

Mike Jones <Michael.Jones@microsoft.com> Fri, 24 July 2015 18:58 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9D7D1A1F1D for <unbearable@ietfa.amsl.com>; Fri, 24 Jul 2015 11:58:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mcNPV__Qjt3H for <unbearable@ietfa.amsl.com>; Fri, 24 Jul 2015 11:58:26 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0132.outbound.protection.outlook.com [207.46.100.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86AE31A8854 for <unbearable@ietf.org>; Fri, 24 Jul 2015 11:58:26 -0700 (PDT)
Received: from BY2PR03MB442.namprd03.prod.outlook.com (10.141.141.145) by BY2PR03MB441.namprd03.prod.outlook.com (10.141.141.142) with Microsoft SMTP Server (TLS) id 15.1.225.13; Fri, 24 Jul 2015 18:58:24 +0000
Received: from BY2PR03MB442.namprd03.prod.outlook.com ([10.141.141.145]) by BY2PR03MB442.namprd03.prod.outlook.com ([10.141.141.145]) with mapi id 15.01.0225.018; Fri, 24 Jul 2015 18:58:24 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Tony Arcieri <bascule@gmail.com>, Jim Fenton <fenton@bluepopcorn.net>
Thread-Topic: [Unbearable] JWS
Thread-Index: AQHQxf2LrXyN25oYS0WGLqzBTojPR53q642AgAAKc4CAAAJOAIAAAIuA
Date: Fri, 24 Jul 2015 18:58:24 +0000
Message-ID: <BY2PR03MB442B981834FD5B33291B020F5810@BY2PR03MB442.namprd03.prod.outlook.com>
References: <CABkgnnVFBRz44HwGwpmoc8PKk+5-Dq4Zxvu9k0TYB9dTnT58Og@mail.gmail.com> <CAHOTMV+MWvpbQh1S7PvVu0X8UKH8Zy9_pF1zwhv4yMAOajW=AA@mail.gmail.com> <55B287EB.2090301@bluepopcorn.net> <CAHOTMVK9szG2SOa0Wve9dMAiq-dWY+2-c8Wn5t-abrMSQcg_3Q@mail.gmail.com>
In-Reply-To: <CAHOTMVK9szG2SOa0Wve9dMAiq-dWY+2-c8Wn5t-abrMSQcg_3Q@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;
x-originating-ip: [12.130.117.147]
x-microsoft-exchange-diagnostics: 1; BY2PR03MB441; 5:5mHkalfKU109dXtHaEqxWRpbd6GG/9eoTrj0Zb2jfXZOZKJxOMhIi0c1vVei/mLonLghez9HrJbm4Njjd+gASy2ltbuQHJtJAgnWg7aeg+GA6oBrIdHF0F5Ywn2azCbWr455mtae+zrHADxRcVkZFQ==; 24:evJ8xzBXwKHp3pdnja/cOOnL56/yOqgi6nMacWKJ1SSNoDXx1mHJrvoENhxg492du7ZR1eQn8ZkAimAdI+qjDakmJFj5dnc7vOUAAy6DxO4=; 20:Sw4xW0g8WmtJ0J6WxUXHK5Cj8hw7a/w+AS94A/2trwD4KMSpWXQRZ/cQUnoeBbg3I3C6Gd4AXo1ExxhaG7UeDw==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY2PR03MB441;
by2pr03mb441: X-MS-Exchange-Organization-RulesExecuted
x-microsoft-antispam-prvs: <BY2PR03MB4411A349D15A81DD6219E54F5810@BY2PR03MB441.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(108003899814671);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401001)(5005006)(3002001); SRVR:BY2PR03MB441; BCL:0; PCL:0; RULEID:; SRVR:BY2PR03MB441;
x-forefront-prvs: 0647963F84
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(24454002)(377454003)(86362001)(66066001)(122556002)(93886004)(46102003)(106116001)(19617315012)(86612001)(99286002)(19609705001)(2656002)(19300405004)(19580395003)(5003600100002)(76576001)(92566002)(87936001)(54356999)(77156002)(74316001)(5002640100001)(16236675004)(10090500001)(50986999)(77096005)(5001960100002)(2900100001)(76176999)(2950100001)(102836002)(15975445007)(19625215002)(33656002)(189998001)(5001770100001)(62966003)(40100003)(19580405001); DIR:OUT; SFP:1102; SCL:1; SRVR:BY2PR03MB441; H:BY2PR03MB442.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
Content-Type: multipart/alternative; boundary="_000_BY2PR03MB442B981834FD5B33291B020F5810BY2PR03MB442namprd_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Jul 2015 18:58:24.1313 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2PR03MB441
Archived-At: <http://mailarchive.ietf.org/arch/msg/unbearable/lLq-CDpFNsi5qpJuTI2e_du7jf8>
Cc: "unbearable@ietf.org" <unbearable@ietf.org>, Martin Thomson <martin.thomson@gmail.com>
Subject: Re: [Unbearable] JWS
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Jul 2015 18:58:28 -0000

When using the JWS Compact Serialization http://tools.ietf.org/html/rfc7515#section-3.1, which is what Token Binding would use, attackers can’t choose algorithms because the algorithm identifier is included in the integrity-protected information.

                                                            -- Mike

From: Unbearable [mailto:unbearable-bounces@ietf.org] On Behalf Of Tony Arcieri
Sent: Friday, July 24, 2015 11:54 AM
To: Jim Fenton
Cc: unbearable@ietf.org; Martin Thomson
Subject: Re: [Unbearable] JWS

On Fri, Jul 24, 2015 at 11:46 AM, Jim Fenton <fenton@bluepopcorn.net<mailto:fenton@bluepopcorn.net>> wrote:
I would point to the fact that we (now) have libraries that have been vetted as a reason to use JWS, not the other way around.

(or maybe that's what you meant)

If finding a single vuln meant that a library is "vetted", OpenSSL would be an impenetrable fortress by now.

This particular vulnerability speaks to what I think is a design flaw that adds sharp edges to the format, namely that an attacker can choose algorithms as part of a malleable portion of the message which the verifier needs to interpret in order to verify the messages.

It's not an intractable problem, but it is one that leads to implementation difficulties, and is one of the reasons I've avoided JWT and instead used bearer token formats where these sort of problems are impossible by design.

I would like to leverage tokbind, but it saddens me that to do so I might have to add this attack surface back.

--
Tony Arcieri