[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | MTG AG |
| Message-ID | <[email protected]> |
Am 30.09.25 um 09:23 schrieb Simon Josefsson: > Falko Strenzke<[email protected]> writes: > >> I have to correct myself: you are right, it doesn't work with CMS >> because CMS, even though it also signs the message in pure mode, it >> signs the message directly and not the hash as OpenPGP. So basically >> the conclusion is that the attack is typically prevented because >> OpenPGP uses the pure mode to sign hashes, and other protocols >> typically will use the pure mode to sign the message directly. > Is there a cross-protocol attack if CMS were to sign a message hash? > Would that CMS signature be extractable and valid in a PGP context? No. I argued that it is, but I had missed that while OpenPGP uses the pure variants (i.e. not the pre-hashing ones) of ML-DSA and SLH-DSA to sign a hash, CMS uses the pure variants to sign the message directly. This is what Aron had pointed out. It means that an attacker would have to trick the CMS user to sign a crafted hash as the message, which is not a realistic threat in my view. Best regards, Falko > > I think the point of a context field is to mitigate cross-protocol > attacks, but I've always found them to be fragile (and it looks like the > OpenPGP context separation will be weak too) so robust application > protocols has to do their own context separation between signing > systems. > > /Simon > >> Cheers, >> Falko >> >> Am 29.09.25 um 17:06 schrieb Falko Strenzke: >>>> I believe not even the very liberal CMS lets you do that, for >>>> instance ML-DSA is specified in pure mode only. >>> We are using ML-DSA in pure mode for OpenPGP as well. CMS works thus >>> works perfectly for such attacks. >>> -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected] Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.9 KB) - not displayed