[saag] Re: Using a MAC instead of a cryptographic hash can l ead to vulnerabilities

Deirdre Connolly <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAFR824zCFtaD9iWa_ER2wfp=YyyWPOtkFtTFPNFgg94Y1nLGRQ@mail.gmail.com>
> This draft proposes to register a MAC registry for RSVP. The goal is to
move away from the currently hardcoded HMAC-MD5 in the future
https://datatracker.ietf.org/doc/draft-atkinson-teas-rsvp-auth-v2/

Aha cool! Thanks for the link

> Having a registry for hashes and using them in HMAC is slow and limits
crypto agility but is at least secure. Having a registry for MACs and using
them for hashes or KDFs would be completely insecure in general.

💯

On Thu, Mar 20, 2025, 8:52 PM John Mattsson <[email protected]>
wrote:

> >I am not aware of any IANA registry in I*TF that registers MACs,
>
> This draft proposes to register a MAC registry for RSVP. The goal is to
> move away from the currently hardcoded HMAC-MD5 in the future
> https://datatracker.ietf.org/doc/draft-atkinson-teas-rsvp-auth-v2/
>
>
> There were discussions to change the HMAC register in SCTP to a MAC
> registry to enable other MACs such as KMAC, CMAC, GMAC, but that is not in
> the current draft.
> https://datatracker.ietf.org/doc/draft-ietf-tsvwg-rfc4895-bis/
>
> >A message authentication code (MAC) is not a cryptographic hash
>
> Definitely not. MACs are as little hashes as signatures are. People have a
> lot of wrong ideas about MACs, such as them being hash functions, not
> revealing the info about the message, and being possible to truncate. All
> of which are wrong in general. In addition to CMAC, GMAC is definitely not
> a hash function. Sometimes people also confuse PRFs, MACs, and hash
> functions. CMAC is a PRF and therefore a MAC, but it is not a hash.
>
> Having a registry for hashes and using them in HMAC is slow and limits
> crypto agility but is at least secure. Having a registry for MACs and using
> them for hashes or KDFs would be completely insecure in general.
>
> John
>
>
>
> *From: *Deirdre Connolly <[email protected]>
> *Date: *Thursday, 20 March 2025 at 18:10
> *To: *IETF SAAG <[email protected]>
> *Subject: *[saag] Using a MAC instead of a cryptographic hash can lead to
> vulnerabilities
>
> On the question in the meeting just now of help with using HMAC, which
> work for that I think is a good idea, there was a reply of registering it
> as a 'hash' in places in the IETF which handles them: this is a category
> error that has security implications.
>
>
>
> A message authentication code (MAC) is not a cryptographic hash,
> especially in regards to it being keyed, and using a MAC when you actually
> need to use a hash can lead to vulnerabilities:
> https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking
>
>
>
> I am not aware of any IANA registry in I*TF that registers MACs, or if one
> is necessary. Perhaps guidance documents from CFRG or elsewhere would be
> helpful, RFC2104 is pretty tight on this score.
>
>
>
> Cheers,
>
> Deirdre
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.