[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Mon 2025-09-29 17:55:45 +0100, Andrew Gallagher wrote:
> On 29/09/2025 16:06, Falko Strenzke wrote:
>> My conclusion from this is that protocols should generally start signed 
>> data with a long enough magic constant, as this makes crafting such 
>> cross-protocol aliases much less feasible.
>
> How long is "long enough"? Is it sufficient to use a magic number that 
> is in common use and/or non-colliding? Or would we need to use a minimum 
> bit length of magic to also make hash collisions infeasible? If we used 
> both a magic number and a random salt, would the security properties be 
> combined, or would they interfere?

This question is exactly what the `context` octet-string input for more
recent signature primitives (ed448, ml-dsa, etc) is supposed to take
care of.

I don't think there's a principled answer to the "long enough" question
-- there's just "how do we separate domains so that a single key can't
create a signature that can effectively be used in two domains?"  The
answer for new protocols, once primitive libraries that support this are
widely-available, is to use the `context` input.

It looks like the consensus of the WG is that we've missed the window
for the signatures outlined in this draft, but future codepoints (or
future versions of signatures) could indeed adopt a context string for
those underlying signing primitives that support it.

       --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE-----

wr0EARYKAG8Fgmja61UJEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z
LnNlcXVvaWEtcGdwLm9yZ8qfMLiRJfaAUyEXiMEl4Yc7woO1DLnPw3uiuQTapM+v
FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAAOLHAP9TyuJwWPftstw0gBx4QXVAzbGh
yrVWi8KBfNil7OTkFwEA8bAlON/PRjquWlqcKgpi3kDfGkRsriPN842InV5FJg0=
=YhkR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.