[openpgp] Re: on the risks of AEAD as signature [was: Re : draft-ietf-openpgp-persistent-symmetric-keys-02.txt]
Andrew Gallagher <[email protected]> Fri, 7 Nov 2025 18:16:04 +0000
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 07/11/2025 00:22, Daniel Kahn Gillmor wrote: > > Thanks for this note. I'm not enough of a cryptographer to understand > the risks clearly here, but my loose understanding of the "invisible > salamanders" paper suggested that it's possible to create two messages > that would have a colliding AEAD tag (maybe under different keys?): > > https://eprint.iacr.org/2019/016 > > That is, it describes GCM as a "non-committing AE" scheme, and indicates > that a modified primitive is necessary to make it "committing". Is this > sufficient to behave as a signature for our purposes? Isn't this why we specified an HKDF step in SEIPDv2? We could do the same thing here. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]