[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
I appreciate the detailed thought in this exchange that is put into how
these things will actually be used, and what the risks are for those
likely uses.

I'm not sure how much this draft needs to spell those out (which i take
to be something like Falko's position) and how much it can just describe
the mechanism as a stepping stone for future applicability work (which
is a sketch of what i'm reading as Daniel's position).  I personally
tend to want to see at least some clear use case rationales and thoughts
about security risks over pure mechanism for mechanism's sake.  I'd be
curious to hear what other members of the working group think about this
tradeoff.

Specific comments interleaved below:

On Wed 2025-08-20 15:34:49 +0200, Falko Strenzke wrote:
> Am 19.08.25 um 15:52 schrieb Daniel Huigens:
> Any ambiguity of an HMAC signature would have to be ruled out.

Falko, what if we took the fact of symmetric cryptography out of the
picture entirely here.  Do you think that OpenPGP asymmetric signatures
have this kind of ambiguity?

Presumably, the signing secret key is known only to the keyholder
(shared among their multiple devices, perhaps, or just used for the sake
of backup and recovery with a single device).  If Alice re-signed a
message from Bob today, the signature would still be "Alice's
signature", right?  And therefore wouldn't be normally applicable to a
message from Bob.

So if we're talking about how to make timestamping (or similar) claims
about other signatures, that's mechanism we'd need to flesh out even in
the case of non-symmetric signing algorithms.

Does anything from draft-gallagher-openpgp-signatures address this
concern?

> I think the draft needs to address the security considerations that 
> apply to introducing HMAC as a signature scheme. It is just not 
> equivalent to asymmetric signatures.

Falko, can you propose some text for the security considerations section
that would address your concerns?  Having something concrete might make
the conversation more fruitful.

    --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQRjrBGOWy5dZsiKhad4C4VO2cK0lgUCaLdgbgAKCRB4C4VO2cK0
ljXVAQDPdgXiGymRhKXIkAL2+uDmuWX3Lvu6ljb0k8ijct55xQEAl945N2IW+mIb
XpKDmi0xwqxwSkg8yZ4BWXBqv3l5Fwo=
=9oKF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.