[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Falko Strenzke <[email protected]> writes: > I have to correct myself: you are right, it doesn't work with CMS > because CMS, even though it also signs the message in pure mode, it > signs the message directly and not the hash as OpenPGP. So basically > the conclusion is that the attack is typically prevented because > OpenPGP uses the pure mode to sign hashes, and other protocols > typically will use the pure mode to sign the message directly. Is there a cross-protocol attack if CMS were to sign a message hash? Would that CMS signature be extractable and valid in a PGP context? I think the point of a context field is to mitigate cross-protocol attacks, but I've always found them to be fragile (and it looks like the OpenPGP context separation will be weak too) so robust application protocols has to do their own context separation between signing systems. /Simon > Cheers, > Falko > > Am 29.09.25 um 17:06 schrieb Falko Strenzke: >>> I believe not even the very liberal CMS lets you do that, for >>> instance ML-DSA is specified in pure mode only. >> >> We are using ML-DSA in pure mode for OpenPGP as well. CMS works thus >> works perfectly for such attacks. >> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE----- iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmjbhYYUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFov8CAQDrSw8lLEtR YMGyqt6Lu/SyuInwtvZq8xzCHgTKVTRcQwEAx0NlugS2ltAJ6P4jQSAEm7QFbX03 pLMacGQckD6i0QM= =NZf+ -----END PGP SIGNATURE-----