Re: [Unbearable] JWS

Mike Jones <Michael.Jones@microsoft.com> Sat, 25 July 2015 04:30 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E52171B2A1C for <unbearable@ietfa.amsl.com>; Fri, 24 Jul 2015 21:30:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hEajKkX4Ct8s for <unbearable@ietfa.amsl.com>; Fri, 24 Jul 2015 21:30:54 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0733.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::733]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FD001B2A19 for <unbearable@ietf.org>; Fri, 24 Jul 2015 21:30:54 -0700 (PDT)
Received: from BY2PR03MB443.namprd03.prod.outlook.com (10.141.141.152) by BY2PR03MB394.namprd03.prod.outlook.com (10.141.141.13) with Microsoft SMTP Server (TLS) id 15.1.225.13; Sat, 25 Jul 2015 04:30:49 +0000
Received: from BY2PR03MB442.namprd03.prod.outlook.com (10.141.141.145) by BY2PR03MB443.namprd03.prod.outlook.com (10.141.141.152) with Microsoft SMTP Server (TLS) id 15.1.225.13; Sat, 25 Jul 2015 04:30:48 +0000
Received: from BY2PR03MB442.namprd03.prod.outlook.com ([10.141.141.145]) by BY2PR03MB442.namprd03.prod.outlook.com ([10.141.141.145]) with mapi id 15.01.0225.018; Sat, 25 Jul 2015 04:30:48 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Tony Arcieri <bascule@gmail.com>, Jim Fenton <fenton@bluepopcorn.net>
Thread-Topic: [Unbearable] JWS
Thread-Index: AQHQxf2LrXyN25oYS0WGLqzBTojPR53q642AgAAKc4CAAAJOAIAAAIuAgAADwACAAHtFAIAAFG0AgAAIvgCAAADyEA==
Date: Sat, 25 Jul 2015 04:30:48 +0000
Message-ID: <BY2PR03MB442CC8201A4FED97C5E750BF5800@BY2PR03MB442.namprd03.prod.outlook.com>
References: <CABkgnnVFBRz44HwGwpmoc8PKk+5-Dq4Zxvu9k0TYB9dTnT58Og@mail.gmail.com> <CAHOTMV+MWvpbQh1S7PvVu0X8UKH8Zy9_pF1zwhv4yMAOajW=AA@mail.gmail.com> <55B287EB.2090301@bluepopcorn.net> <CAHOTMVK9szG2SOa0Wve9dMAiq-dWY+2-c8Wn5t-abrMSQcg_3Q@mail.gmail.com> <BY2PR03MB442B981834FD5B33291B020F5810@BY2PR03MB442.namprd03.prod.outlook.com> <301BBBAC-1CF8-43BD-9865-52D8F725BA84@ve7jtb.com> <CAHOTMV+VYnHUeFC1_xcWg6OVY42k4LDBcc2v119u86cgvgHj4Q@mail.gmail.com> <55B305FE.8050308@bluepopcorn.net> <CAHOTMVKe2rr-2VMMKCsCJx=mGz9coei75hNz-NYJOAHXyxCLDQ@mail.gmail.com>
In-Reply-To: <CAHOTMVKe2rr-2VMMKCsCJx=mGz9coei75hNz-NYJOAHXyxCLDQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;
x-originating-ip: [12.130.117.133]
x-microsoft-exchange-diagnostics: 1; BY2PR03MB443; 5:X3MTo82p5jPYYbrB+dLlhaJHvsic8EBBah453TvTNEP/wHw3eMTWv7eYNZjeUFEIuVbAMtqBCnBxAU165LWnRErfwdRqt1iq8WFCm9EvK8GfqhqdvOhEEfBD65d8cG5oK1MkD24qLwul1pNVBU3OsQ==; 24:xMa7Rbjy/nuluFLRJ7LcqQoYASuQiguAKoj9Lt5Po2OD7R7/N1hrGfr9AAv99Czmt8LzTFTM8xP0HBsTZVIV5xUARZU5WYkl8RekPi68Ejs=; 20:XOai99/G+dUg9A64QZYrXyL3KEszX/vwtgkQQlNkJMNGdpVEPuTfVmkxmy5q9PfmeS2B5ZbnmzL4yIyTbTpsCQ==
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:; SRVR:BY2PR03MB443; UriScan:; BCL:0; PCL:0; RULEID:; SRVR:BY2PR03MB394;
by2pr03mb443: X-MS-Exchange-Organization-RulesExecuted
x-microsoft-antispam-prvs: <BY2PR03MB443CB390883977329CBBCB6F5800@BY2PR03MB443.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(108003899814671);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401001)(5005006)(3002001); SRVR:BY2PR03MB443; BCL:0; PCL:0; RULEID:; SRVR:BY2PR03MB443;
x-forefront-prvs: 0648FCFFA8
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(24454002)(377454003)(74316001)(10090500001)(76176999)(92566002)(86612001)(33656002)(19625215002)(189998001)(46102003)(86362001)(5003600100002)(19580405001)(16236675004)(5002640100001)(106116001)(54356999)(50986999)(19300405004)(5001960100002)(122556002)(19609705001)(77096005)(87936001)(15975445007)(19580395003)(62966003)(77156002)(2950100001)(76576001)(66066001)(102836002)(40100003)(2656002)(93886004)(2900100001); DIR:OUT; SFP:1102; SCL:1; SRVR:BY2PR03MB443; H:BY2PR03MB442.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
Content-Type: multipart/alternative; boundary="_000_BY2PR03MB442CC8201A4FED97C5E750BF5800BY2PR03MB442namprd_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jul 2015 04:30:48.3255 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2PR03MB443
X-Microsoft-Exchange-Diagnostics: 1; BY2PR03MB394; 2:tEYnHo1AhXiYRYh6oAWO4qBHjWSaM9kYbbi1EKXa+hO2BfaHRrPuzXc/LYIUulW9c0GvZFuzvlEt+YC/2hyXIFv25qQelERN5fTX4UKjQj8CRns987jCm7CkA0IIg+M9DXqTdJNm6fgkwKcB0/8olS5OlHX1eUYt2cjnudiM6cE=; 3:vIZs5f0l2AOcVVG4e748J3Pev/5xEXpShogioiQgPal39hHf7BZH243PWUC6HO51XdExKSvQQmW1dc6+g6Fogoatt2iJOMpk71HKA/ycqcuZ9q38kC2I1n54OfcwMcI/TE4lMtL/lPIdxWgqueFCXA==; 25:9iz05gTnBTbwSXWJ/az0z2tm5zbkP2c14q2BRXYdzG5xxatp1WqaBulhWFOoMus4scRx+B8cxXKEhZyQGuQbsUcdVuzHmt/uW+iwFG+K4duFoXKml4feHVnM0Xeu7nrUjWy+XB0rAGtY+wBPTGebY9ugsl+lNPlFfOBA6xSKF5dAstfGLIDiDjZrXbqowIAKc95WPRCCDhE7wWt968VjHqRNHpAJDBdMwQveiDb8azGv/JFEDri9AKMZObh3GaK/3juNulpH3IgWwV+zZLnx9g==
X-Microsoft-Exchange-Diagnostics: 1; BY2PR03MB394; 20:EMUSduMjoNqwEMAhtsBYQFz0wfACAuQEabsXp3L9//PWMsBz8F6WB+EI79LeGf5yOnV78kAcWnimC05hzJX5vY8cxvUgW2pvqKedsedtRV7xRe8Ls1XN4vUwWZio06/fxI7aaYYN0EyzuAIXzhATLWvrOA7uRJnz/y473mvXSVicqP8pLGKpH7Ciyqn8PTU7C6Zz2xFyAAcRKwwuZVls+eoM6mDXW7XT9x19mMF6Dp0aTqKNxmcUfA+yW8qUmuie3Y7BYi4md6FWly6RRV/IuFMwkjQLkgbL1sgVuLg6d6zaEyJHuZCVnwzCaRTiCux+ufcaOBK61fPwUkrqL7VadZSSZzZ+32kTLxC5pDHg6tch1O4abOh+39NMz3Emud4hcV0O3oNBpoobi2ZOhYZANsNHEo8KeXmw1TBKqz0lz6fF20oK05YNF/AwOdAExPPFn4uGL572sjK2ICeuo9/DyZgT9X9J+xLAPH8I6XKbIVzs2rE3P1EQBRhIovD55HDp; 23:IZ7rYJI7nCmcwKBdnpuMjfWsBB3tkalyZ1Fhp3IymhUb4J8nLNoRqWxtQxu0si7zpVpWz2QXUjr8w5MPI4so/ZI3qMU4CNvXlH28yed+E3mEmwKbGXi8fF18/ljkr55vtJA6zKD7Y3PVj11b5qOQ2VxWGSOyy5FFhPHeMKoIvEo1pQMRr/dHhHG1/WbmIYeQWgNGoVpAcluEYRRRHMno3KXuhn/k8lwTX1Zitszka8kK6pdr7YX8MxPboIMEyuCJ
BY2PR03MB394: X-MS-Exchange-Organization-RulesExecuted
X-OriginatorOrg: microsoft.com
Archived-At: <http://mailarchive.ietf.org/arch/msg/unbearable/zIRGwKcxEBWSG_mbwre4POtLcvg>
Cc: John Bradley <ve7jtb@ve7jtb.com>, "unbearable@ietf.org" <unbearable@ietf.org>, Martin Thomson <martin.thomson@gmail.com>
Subject: Re: [Unbearable] JWS
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Jul 2015 04:30:57 -0000

What attacks are you worried about Tony?  As I’d written earlier, an attacker can’t change the algorithm for signed/MACed content, since the algorithm identifier is integrity protected and the signature will be rejected if not produced by the algorithm protected in the header.

Also, I’ll observe that verifying that the algorithm used is currently acceptable to the application is a standard part of any cryptographic workflow.  Just like you wouldn’t accept an MD5 MAC because it’s not in your acceptable algorithms list, you wouldn’t accept “none” for the same reason.  This necessary algorithm hygiene step is explicitly required by JWS, with this language:
   Finally, note that it is an application decision which algorithms may
   be used in a given context.  Even if a JWS can be successfully
   validated, unless the algorithm(s) used in the JWS are acceptable to
   the application, it SHOULD consider the JWS to be invalid.

                                                            Best wishes,
                                                            -- Mike

From: Tony Arcieri [mailto:bascule@gmail.com]
Sent: Friday, July 24, 2015 9:15 PM
To: Jim Fenton
Cc: John Bradley; Mike Jones; unbearable@ietf.org; Martin Thomson
Subject: Re: [Unbearable] JWS

On Fri, Jul 24, 2015 at 8:43 PM, Jim Fenton <fenton@bluepopcorn.net<mailto:fenton@bluepopcorn.net>> wrote:
I agree that a library that has had a bug found and fixed does not mean that it has been vetted. I expressed this wrong.

But having a library that has had at least some degree of use and debugging is an advantage over doing something different and writing new libraries from scratch.

I don't think JWS/JWT are the only game in town. There are alternatives to consider which don't involve "writing new libraries from scratch"

--
Tony Arcieri