Re: Adding a nounce before hashing as covert channel

Andrew Gallagher via Gnupg-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
On 16 Dec 2024, at 14:51, Werner Koch <[email protected]> wrote:
> 
>> taking plaintext covert channels as a serious threat. Also, v5
>> signatures have extra free-text fields (filename, timestamp) that are
>> hashed-in before the main document, rather than as subpackets.
> 
> Yes, they can be used.  But your WG removed the bug fix (i.e. hashing
> the meta data).  And that is the very reason why it is not possible to
> support that new signing format.

Werner, *you* proposed a solution for this in the LibrePGP draft:
https://datatracker.ietf.org/doc/html/draft-koch-librepgp#section-5.2.3.33

> This subpacket MAY be used to protect the meta data from the Literal Data Packet with V4 signatures

I then proposed extending this mechanism to v6 signatures:
https://datatracker.ietf.org/doc/html/draft-gallagher-openpgp-literal-metadata

> This document introduces the missing integrity check by adopting and extending the "Literal Data Meta Hash" subpacket from [LIBREPGP], section 5.2.3.33.

And then *you* told *me* that it wasn’t worth the effort implementing the fix that *you* invented:
https://lists.gnupg.org/pipermail/librepgp-discuss/2024/000005.html

> Sure, you may use it for v6 signatures. But after all why should you do it, given that it was removed from crypto-refresh for some incomprehensible reason.

Are these serious questions for which people can propose serious answers, or is it just a gish gallop? Because it feels like we’ve been going around the same circles for over a year now.

A

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmdgRckACgkQXB7EBNWQ
ZinjDg//WK359zq7eOX7OU6sF4j+ag9pIvFAHz4svVZKZa+JfH7/6sfkOl7ox1FV
NXP2NsgwQEHgDTr1Cl/1W5RTbde2PVDOFcZl/bbB9Xi3F21THEaM0u/+9zyL0jS8
LeHtWKHlVjQtJGj7mrVpdSkxTwmFMkdiOSJLLJlG3DE+SGFiJwp+mf4bKgXoRm6G
5R7xsVm3ASsQdOwXrUEgu2sN/rCp1OOO6eI2H50A+QAkmZsdPwaajjSnOfMcCtll
caPry6MaHFpH/sZZ5DpE6uXYOj7+KWpu2l4INzBMvmCTvbKnKvJ3zOZmX7Z2q5RX
vi53mHnAsn89yl6eq07XV7Ug+WpTaQid0H/ykZtG9IDTwjf029argk/ZG/PtE2Sg
6znMF+aqaQ7Xp+TCaVPkxKRAaCLS4i/Z/o7VwF9yShqGRpPOuZypcWdB7xeLVCDV
9CZZJ5vNrlw2AGJws3Npcp33Q4M9FoI4LtAQru9gc+RoUJ/8ufMKESKwNto3iVI8
ht9okCgvfZID4prKdtG5vqAAkdVsJSOvis3oj0oSRAQQh+WfuDzsiCU0qec7nwat
8vNXjGQEtamJqH2ruetBQzOtezEyxnDXIe0hiLzQLK7eIez4jUHRTAKtP/HE9Ju7
+WNhlnyWkQvVdKav5Rbu+GV78SuqpUcPmxCYGvv0SG6KwyZIYNU=
=ngD3
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.