[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <RFGDrNu3L_AfhbXTDmnSsxmanhg7VixejS0_WTsRaRTV_Xn1NTd4ON2ypQsHSK7yxNViLCe1Bo2skTTQaIoi4h-bcKsTRp4hbUCVyJ-iXxg=@protonmail.com>
Hi Falko (and dkg),

Thanks for the detailed considerations!

I'll answer your questions in reverse :)

On Thursday, September 4th, 2025 at 16:18, Falko Strenzke <[email protected]> wrote:

> - Do you think that using time stamping signatures is the right way?

From reading section 3.5 and 3.6 of draft-gallagher-openpgp-signatures, my understanding is that timestamping signatures are to be used to sign documents, while Third Party Confirmation Signatures (0x50) are to be used to sign signatures. The latter is closer to the use case I described previously. (That doesn't necessarily mean that creating a timestamping signature with a symmetric key isn't useful, perhaps it is, but it's not what I had in mind originally.)

Further, section 3.6 says:

> By default, a Third Party Confirmation signature makes no claim about the validity of the other signature, just its existence, and makes no claim whatsoever about the subject of that signature. This interpretation MAY be modified by adding notation subpackets, the meaning of which are application-dependent.

Which I think doesn't quite reach your goal of fully specifying a mechanism. However, personally I think it could be defensible to define a subpacket or notation for this purpose (of denoting whether the countersigned signature was observed to be valid or invalid) in draft-gallagher-openpgp-signatures. Andrew is currently on vacation so we may have to wait for his opinion :)

In any case, I'm happy to point from draft-ietf-openpgp-persistent-symmetric-keys to draft-gallagher-openpgp-signatures for suggestions on how to use persistent symmetric signing keys.

> (...) the points to cover in the Security Considerations seem mainly:
>
> - Guidance on the symmetric key size

Sounds reasonable.

> - Guidance on symmetric key exchange between users

Currently, the draft doesn't talk about sharing/exchanging symmetric keys between users at all, not even as a potential use case. If we want to talk about it in the security considerations, I think it would be good to also mention it earlier, so that the security considerations don't fully come out of the blue. For example, in Section 3 we could say:

> In contexts that do not require asymmetric cryptography, such as secure data storage where the same user encrypts and decrypts data, or in cases where two users have a pre-shared symmetric key, symmetric cryptography can be used to take advantage of these benefits.

(new text in bold).

And as I said before, even though this is not the use case I originally had in mind, if others also think this is useful, I wouldn't be opposed to mentioning it.

> - Guidance on how to display symmetric "signatures" to users

UX considerations are always difficult and I'm not sure what guidance you have in mind so it's a bit difficult to comment, but I think it may be worth commenting on the differing security properties, and suggest to make those clear to the user in some way, without necessarily prescribing how to do so, exactly.

> - Do you agree with this approach for the security considerations?

Modulo the comments above, yes :)

> Should I suggest a text for the security considerations as outlined above?

That would be great, thanks a lot!

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.