[saag] Using a MAC instead of a cryptographic hash can lead to vulnerabilities

Deirdre Connolly <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAFR824wwPd0HK4O+snkr1v9TRQ8D3b=U9xiicXCJh8+rB1DwWw@mail.gmail.com>
On the question in the meeting just now of help with using HMAC, which work
for that I think is a good idea, there was a reply of registering it as a
'hash' in places in the IETF which handles them: this is a category error
that has security implications.

A message authentication code (MAC) is not a cryptographic hash, especially
in regards to it being keyed, and using a MAC when you actually need to use
a hash can lead to vulnerabilities:
https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking

I am not aware of any IANA registry in I*TF that registers MACs, or if one
is necessary. Perhaps guidance documents from CFRG or elsewhere would be
helpful, RFC2104 is pretty tight on this score.

Cheers,
Deirdre

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.