Re: removing keygen from HTML

Harry Halpin <[email protected]> Tue, 31 May 2016 04:40:30 -1000
Newsgroups gmane.org.w3c.tag
Message-ID <CAE1ny+7JDd00QCK1DU5W_WRrS+Vzg6URCw8r+_YB-Lnzcsj0GA@mail.gmail.com>
--001a1135522acf87560534245a7c
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Tue, May 31, 2016 at 3:43 AM, Daniel Appelquist <[email protected]> wrote:

> Hi Folks - the TAG (in the person of Travis) has written on this topic:
>
> https://w3ctag.github.io/client-certificates/#replacing-keygen
>
> As noted, it represents the rough consensus of the TAG on this issue.
>


My point was that the TAG should know that the W3C Web Authentication
Working Group has started, and the W3C Web Authentication AI I believe
fulfils most if not all of these use-cases in a way that improves on
<keygen>, and the plan is to be in browsers by end of the year.

One could argue to keep <keygen> enabled till when Web Authentication API
is in browsers.

Also, as <keygen> is currently non-interoperable and specified in only one
browser and so could be removed on those grounds below from the HTML spec
as per W3C Process. The former would probably cause less complaints from
the WebID+TLS user group that is on this mailing list.




>
> Dan
>
> On Tue, 31 May 2016 at 13:33 Eric Mill <[email protected]> wrote:
>
>> The original email said: "Since the TAG, or its members, appear to have
>> opinions about our spec, we'd be grateful to hear them." It'd be most
>> productive for this thread's discussion to at least be initiated by a
>> member of the TAG.
>>
>> -- Eric
>>
>> On Tue, May 31, 2016 at 8:12 AM, Harry Halpin <[email protected]>
>> wrote:
>>
>>>
>>>
>>> On Tue, May 31, 2016 at 1:40 AM, Reto Gm=C3=BCr <[email protected]> wrote:
>>>
>>>> On Tue, 31 May 2016, at 10:04, Harry Halpin wrote:
>>>>
>>>> I do not know anyone from the cryptographic or security community that
>>>> would support keeping <keygen>. Indeed, the default response from the
>>>> security/crypto community would be to drop <keygen> due to legacy usag=
e of
>>>> MD5 and violation of security boundaries (SOP).
>>>>
>>>> That would also be my response if I was employed by the NSA and wanted
>>>> to prevent technologies that allow user controlled strong cryptography=
 and
>>>> decentralized networks of trust (as enabled by webId).
>>>>
>>>>
>>>
>>> Reto,
>>>
>>> That was both an idiotic and offensive statement. Can you explain how
>>> amateur crypto and home-brewed protocols that no-one in the security or
>>> crypto community reviewed or supports is the way to fight the NSA?
>>>
>>> Myself and many others support strong cryptography and decentralized
>>> networks of trust, and fully support that effort. Rather than attribute=
 the
>>> use of broken technology to protocols to NSA, it's also possibly due to
>>> lack of education.
>>>
>>> Thus, you may want to look at:
>>>
>>> 1) MD5 security issues are well-known and documented:
>>> http://merlot.usc.edu/csac-f06/papers/Wang05a.pdf
>>>
>>> 2) In practice, the WebID+TLS community should use modern crypto and th=
e
>>> Web Security model rather than attempt to build on top of an broken,
>>> obscure, and unstandardised browser behaviour. If you want to fight the=
 NSA
>>> by building new protocols on the Web, I recommend taking a class that
>>> explains how Web security works. Videos are available from this MIT cou=
rse
>>> explain modern Web Security, including the Same Origin Policy:
>>> https://www.youtube.com/watch?v=3D_1C62Twf0vs
>>>
>>> Hopefully others will be more reasonable, but you may wish to
>>> familiarize yourself with this thread rather than endlessly repeat it.
>>>
>>> https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/pX5NbX=
0Xack
>>>
>>> Note that we're just modernizing with W3C Web Authentication secure and
>>> modern cryptographic one-factor authentication to use modern primitives=
 and
>>> respect user privacy. You are more than welcome to join the Working Gro=
up
>>> as an Invited Expert, although an expert should be aware of the basics =
of
>>> security.
>>>
>>> Although there are a number of inaccuracies in this report in terms of
>>> WebCrypto, it's pretty clear Web Authentication matches all requirement=
s in
>>> Section 6 here:
>>> http://w3ctag.github.io/client-certificates/
>>>
>>> Thus, it makes sense to hold off and deprecate <keygen> after the fall
>>> of this year, when Web Authentication is deployed in browsers. As state=
d
>>> earlier, the "WebID" community can simply use Web Authentication rather
>>> than client certs for authentication.
>>>
>>> That being said, since the only browser that supports <keygen> currentl=
y
>>> is Mozilla, who plans to deprecate regardless of what the TAG says, the=
n it
>>> can also be justified to remove from the standard today as there is no
>>> interoperability.
>>>
>>>    cheers,
>>>        harry
>>>
>>>
>>>
>>>
>>>> Cheers,
>>>> Reto
>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>> --
>> konklone.com | @konklone <https://twitter.com/konklone>
>>
>

--001a1135522acf87560534245a7c
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Tue, May 31, 2016 at 3:43 AM, Daniel Appelquist <span dir=3D"ltr">&l=
t;<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt;<=
/span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8=
ex;border-left:1px #ccc solid;padding-left:1ex"><div style=3D"white-space:p=
re-wrap">Hi Folks - the TAG (in the person of Travis) has written on this t=
opic:<br><br><a href=3D"https://w3ctag.github.io/client-certificates/#repla=
cing-keygen" target=3D"_blank">https://w3ctag.github.io/client-certificates=
/#replacing-keygen</a> <br><br>As noted, it represents the rough consensus =
of the TAG on this issue.<br></div></blockquote><div><br><br></div><div>My =
point was that the TAG should know that the W3C Web Authentication Working =
Group has started, and the W3C Web Authentication AI I believe fulfils most=
 if not all of these use-cases in a way that improves on &lt;keygen&gt;, an=
d the plan is to be in browsers by end of the year. <br></div><div><br>One =
could argue to keep &lt;keygen&gt; enabled till when Web Authentication API=
 is in browsers.<br><br>Also, as &lt;keygen&gt; is currently non-interopera=
ble and specified in only one browser and so could be removed on those grou=
nds below from the HTML spec as per W3C Process. The former would probably =
cause less complaints from the WebID+TLS user group that is on this mailing=
 list.<br><br><br>=C2=A0 <br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div sty=
le=3D"white-space:pre-wrap"><br>Dan</div><div><div><br><div class=3D"gmail_=
quote"><div dir=3D"ltr">On Tue, 31 May 2016 at 13:33 Eric Mill &lt;<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex=
;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">The original=
 email said: &quot;Since the TAG, or its members, appear to have opinions a=
bout our spec, we&#39;d be grateful to hear them.&quot; It&#39;d be most pr=
oductive for this thread&#39;s discussion to at least be initiated by a mem=
ber of the TAG.<div><br></div><div>-- Eric</div><div class=3D"gmail_extra">=
</div></div><div dir=3D"ltr"><div class=3D"gmail_extra"><br><div class=3D"g=
mail_quote">On Tue, May 31, 2016 at 8:12 AM, Harry Halpin <span dir=3D"ltr"=
>&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">hhalpin@ibibl=
io.org</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"=
margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"=
ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quote"><span>On=
 Tue, May 31, 2016 at 1:40 AM, Reto Gm=C3=BCr <span dir=3D"ltr">&lt;<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt;</span> wr=
ote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex=
;border-left:1px solid rgb(204,204,204);padding-left:1ex"><u></u>




<div><span><div>On Tue, 31 May 2016, at 10:04, Harry Halpin wrote:<br></div=
>
<blockquote type=3D"cite"><div dir=3D"ltr"><div><div><div>I do not know any=
one from the cryptographic or security community that would support keeping=
 &lt;keygen&gt;. Indeed, the default response from the security/crypto comm=
unity would be to drop &lt;keygen&gt; due to legacy usage of MD5 and violat=
ion of security boundaries (SOP). <br></div>
</div>
</div>
</div>
</blockquote></span><div>That would also be my response if I was employed b=
y the NSA and wanted to prevent technologies that allow user controlled str=
ong cryptography and decentralized networks of trust (as enabled by webId).=
<br></div>
<div>=C2=A0<br></div></div></blockquote><div><br></div></span><div>Reto,<br=
><br></div><div>That was both an idiotic and offensive statement. Can you e=
xplain how amateur crypto and home-brewed protocols that no-one in the secu=
rity or crypto community reviewed or supports is the way to fight the NSA?<=
br><br></div><div>Myself and many others support strong cryptography and de=
centralized networks of trust, and fully support that effort. Rather than a=
ttribute the use of broken technology to protocols to NSA, it&#39;s also po=
ssibly due to lack of education. <br><br>Thus, you may want to look at:<br>=
</div><div><br>1) MD5 security issues are well-known and documented:<br><a =
href=3D"http://merlot.usc.edu/csac-f06/papers/Wang05a.pdf" target=3D"_blank=
">http://merlot.usc.edu/csac-f06/papers/Wang05a.pdf</a><br><br></div><div>2=
) In practice, the WebID+TLS community should use modern crypto and the Web=
 Security model rather than attempt to build on top of an broken, obscure, =
and unstandardised browser behaviour. If you want to fight the NSA by build=
ing new protocols on the Web, I recommend taking a class that explains how =
Web security works. Videos are available from this MIT course explain moder=
n Web Security, including the Same Origin Policy:<br><a href=3D"https://www=
.youtube.com/watch?v=3D_1C62Twf0vs" target=3D"_blank">https://www.youtube.c=
om/watch?v=3D_1C62Twf0vs</a><br><br>Hopefully others will be more reasonabl=
e, but you may wish to familiarize yourself with this thread rather than en=
dlessly repeat it. <br><a href=3D"https://groups.google.com/a/chromium.org/=
forum/#!topic/blink-dev/pX5NbX0Xack" target=3D"_blank">https://groups.googl=
e.com/a/chromium.org/forum/#!topic/blink-dev/pX5NbX0Xack</a><br><br></div><=
div>Note that we&#39;re just modernizing with W3C Web Authentication secure=
 and modern cryptographic one-factor authentication to use modern primitive=
s and respect user privacy. You are more than welcome to join the Working G=
roup as an Invited Expert, although an expert should be aware of the basics=
 of security.=C2=A0 <br><br></div><div>Although there are a number of inacc=
uracies in this report in terms of WebCrypto, it&#39;s pretty clear Web Aut=
hentication matches all requirements in Section 6 here:<br><a href=3D"http:=
//w3ctag.github.io/client-certificates/" target=3D"_blank">http://w3ctag.gi=
thub.io/client-certificates/</a><br><br></div><div>Thus, it makes sense to =
hold off and deprecate &lt;keygen&gt; after the fall of this year, when Web=
 Authentication is deployed in browsers. As stated earlier, the &quot;WebID=
&quot; community can simply use Web Authentication rather than client certs=
 for authentication. <br><br>That being said, since the only browser that s=
upports &lt;keygen&gt; currently is Mozilla, who plans to deprecate regardl=
ess of what the TAG says, then it can also be justified to remove from the =
standard today as there is no interoperability. <br></div><div><br></div><d=
iv>=C2=A0=C2=A0 cheers,<br></div><div>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 =
harry<br><br></div><div><br>=C2=A0<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex"><div><div></div>
<div>Cheers,<br></div>
<div>Reto<br></div>
<div><div>=C2=A0</div>
</div>
<div>=C2=A0</div>
</div>

</blockquote></div><br></div></div>
</blockquote></div><br><br clear=3D"all"><div><br></div></div></div><div di=
r=3D"ltr"><div class=3D"gmail_extra">-- <br><div data-smartmail=3D"gmail_si=
gnature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div>=
<a href=3D"https://konklone.com" target=3D"_blank">konklone.com</a> | <a hr=
ef=3D"https://twitter.com/konklone" target=3D"_blank">@konklone</a><br></di=
v></div></div></div></div></div></div>
</div></div></blockquote></div>
</div></div></blockquote></div><br></div></div>

--001a1135522acf87560534245a7c--