5 ms·
Yes, Mosh definitely uses OCB3 and is apparently unaffected (just added a FAQ to the website). Still pretty scary though -- this could easily have been Mosh's f
by keithwinstein 8y ago
Yes, Mosh definitely uses OCB3 and is apparently unaffected (just added a FAQ to the website). Still pretty scary though -- this could easily have been Mosh's first real security vulnerability and it would have sucked. We first implemented Mosh's crypto in 2011, shortly after OCB3 was released. If I had started working on Mosh six months earlier, I probably would have picked OCB2.
- tptacek 8y agoI haven't though carefully about this at all, but, if Mosh had used "vanilla" OCB2, would it have been practically vulnerable to this attack? What would be the circumstances?
- loeg 8y agoWhat reasons lead you to select any OCB variant in 2011? Not trying to be snarky -- I am genuinely curious, given the patent landscape at that time and lack of any open source grant.
- keithwinstein 8y agoReasonable question! (1) OCB has long had a patent grant for GPLed software (https://github.com/mobile-shell/mosh/blob/master/ocb-license.html https://github.com/mobile-shell/mosh/blob/master/ocb-license...), so the Rogaway patents were a non-issue even in 2011. (Of course there are other patents on authenticated encryption, e.g. IBM's Jutla patents. I understand why OCB gets singled out because of the Rogaway patents, but my understanding is that all AE modes, and perhaps most computer programs in general, likely implicate some patent.) (2) The crypto experts told us that OCB was the best AEAD mode and that if we are going to put all our eggs in one basket, we should pick OCB. I am pretty happy with the choice and with the lack of traditional cipher negotiation in Mosh. (3) Implementation quality strongly favored OCB. At the time, OpenSSL had no AE modes at all, so we probably would have had to vendor and ship an implementation of something not-OCB, or use a non-AE construction. I understand OpenSSL had a lot of pain implementing GCM in a robust way over the subsequent years -- if we had depended on OpenSSL or tried to use its AE modes, we would have inherited that pain. Given our position of wanting to pick one mode and lock it in (which seems to have paid off), I don't think we could have made a better choice in 2011 than AES-OCB. I might make the same choice today, but would look harder at the other available AE modes in OpenSSL.
- loeg 8y agoThanks! The details really help me understand the options available and why the choice was made. I appreciate your taking the time to answer the question thoroughly.