Re: Solving the key disclosure algorithm weaknesses
Mikael Olsson <[email protected]> Mon, 03 Mar 2003 23:19:10 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Tomasz Grabowski wrote: > > On Fri, 24 Jan 2003, Mikael Olsson wrote: > > > 1. The key disclosure interval needs to be randomized to avoid > > "Moving DDoS" attacks. > > Tomasz suggested 10 secs -- 10 minutes (avg. 5 minutes) > > I think I'd say 20 secs -- 3 minutes (avg ~1.7 minutes) > > I don't like that idea. > [too low - think about number of disclosures in one packet] > It is about 20 minutes of history with your proposition and about 75 with > mine. Anyway, in my opinion ~75 minutes is not enough either... This is assuming 2048-bit pubkey and 160-bit hashes. I still think 128-bit hashes is enough, given the extremely limited time window and so on, but thinking about this lead me to another thing: What happens when we realize 2048-bit pubkey isn't enough? Move to 4096-bit pubkey? That's 512 bytes. Should we be specifying a non-ICMP-based protocol for this? > The minimal time 10 seconds was proposed because it will render moving > DDoS attacks useless (maybe we should think about 5 seconds here... Good point there. The counterpoint would be normal timed disclosure. With a very short period, we run the risk of missing them for "normal" DDoS. On the other hand, the average is much longer, so maybe I shouldn't be worrying about this at all. -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com