Re: Solving the key disclosure algorithm weaknesses

Mikael Olsson <[email protected]> Mon, 03 Mar 2003 23:19:10 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>

Tomasz Grabowski wrote:
> 
> On Fri, 24 Jan 2003, Mikael Olsson wrote:
> 
> > 1. The key disclosure interval needs to be randomized to avoid
> >    "Moving DDoS" attacks.
> >    Tomasz suggested 10 secs -- 10 minutes (avg. 5 minutes)
> >    I think I'd say  20 secs --  3 minutes (avg ~1.7 minutes)
> 
> I don't like that idea.
> [too low - think about number of disclosures in one packet]
> It is about 20 minutes of history with your proposition and about 75 with
> mine.  Anyway, in my opinion ~75 minutes is not enough either...

This is assuming 2048-bit pubkey and 160-bit hashes. I still think
128-bit hashes is enough, given the extremely limited time window
and so on, but thinking about this lead me to another thing:

What happens when we realize 2048-bit pubkey isn't enough?
Move to 4096-bit pubkey? That's 512 bytes.

Should we be specifying a non-ICMP-based protocol for this?
 

> The minimal time 10 seconds was proposed because it will render moving
> DDoS attacks useless (maybe we should think about 5 seconds here... 

Good point there.  The counterpoint would be normal timed
disclosure. With a very short period, we run the risk of
missing them for "normal" DDoS.  On the other hand, the
average is much longer, so maybe I shouldn't be worrying
about this at all.

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com