Re: CTP Issue 22: Authorization Token is obtained by truncating the results of the HMAC_SHA1 computation to retain only the leading 32 bits

Charlie Perkins <[email protected]>
Newsgroups gmane.ietf.seamoby
Organization Nokia
Message-ID <[email protected]>
Hello James,

I don't think it is needed, for two reasons:

- The authorization token is only going to be used once

- The data being protected is only good for a few hundred
   milliseconds at most (typically).

Regards,
Charlie P.


James Kempf wrote:

>Issue 22 suggests that 32 bits isn't enough for the authorization token.
>
>See http://danforsberg.info:8080/draft-ietf-seamoby-ctp/issue22 for details.
>
>Possible resolutions:
>
>1) Make the authorization token longer, say 64 bits.
>2) Keep the authorization token at 32 bits.
>
>Suggested resolution: Make the authorization token longer, say 64 bits.
>Justification: The probability of a birthday attack is proportional to
>2**(sqrt(n)), where n is the number of bits in the identifier. If n is 32,
>then sqrt(n) is 16, which is not enough protection (65536). Making n equal
>64 means sqrt(n) is 32 (over 4 billion) which should be enough.
>
>
>_______________________________________________
>Seamoby mailing list
>[email protected]
>https://www1.ietf.org/mailman/listinfo/seamoby
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.