5 ms·
calling this format "secure" is not sufficient, here is a review that asked the right questions. https://neilmadden.blog/2019/12/30/a-few-comments-on-age/ http
by fXmBeWm3TQ 5y ago
calling this format "secure" is not sufficient, here is a review that asked the right questions.
https://neilmadden.blog/2019/12/30/a-few-comments-on-age/ https://neilmadden.blog/2019/12/30/a-few-comments-on-age/
Unfortunately, the age spec doesn’t document its threat model or the security goals it is intended to achieve so I’m having to read between the lines to work out what was intended.
- est31 5y agoYeah it's definitely not cutting edge on all fronts. Another issue is that the length of the plaintext is being exposed. Simple padding would help mask that in most, if not all, instances.
- upofadown 5y agoIt's for the case where you are concerned about malicious modification and the user is expected to not deal with the ramifications of the error message. This case in particular: $ gpg2 -d backup.tgz.pgp | tar xz So the modified backup file can do bad things before anyone can stop it because gpg will complete the operation before warning of the modification. It doesn't have integrated signature support so that in most cases an attacker can use the public key to entirely replace the file and avoid the bother of some sort of known text attack in the first place. So I think that the use case is so narrow as to disappear. The linked article covers this. That is really all there is. It serves best as a demonstration of what an encryption utility would be like that blows up and errors out on a possible modification, as opposed to completing the operation and returning the error at the end.
- tptacek 5y agoMore on this argument here: https://news.ycombinator.com/item?id=27433186 https://news.ycombinator.com/item?id=27433186 This is, to put it charitably, an idiosyncratic argument about how data encryption is supposed to work.
- upofadown 5y agoThat age does not yet have a data recovery utility is, I think, an interesting point, but it is a different point entirely.
- tptacek 5y agoIf I've confused this for some other idiosyncratic argument about PGP's "authenticated" encryption, I apologize for scrambling the thread. Probably the top-line response re: PGP is that there might be no cryptographic tool in common use with a less coherently documented threat model than PGP.
- some_furry 5y agoHas someone created a Reed-Solomon encoder/decoder CLI program to use with age yet? I think if we did that, the stupid discussion about GPG and framing its lack of IND-CCA2 as a "recoverability feature" would become moot.
- upofadown 5y agoThe single bit error in the discussion was intended to be an extreme example. Typically media errors involve entire media blocks. Often the blocks are missing entirely. I have looked into this a bit and there doesn't seem to be any reason age could not have a recovery utility. It would involve some minor brute forcing to find the next block and block number. It could even skip any 64k block that failed the integrity check so that only authenticated data was recovered. That would be consistent with the general principle about not releasing unauthenticated data that age was created to enbody.
- some_furry 5y agoThe reason I suggested a separate utility, and a composition thereof, is that complexity is the enemy of security. Error-correction and media block-based encryption is a separate utility than what age provides, and should therefore be a separate tool. That separate tool can use age for the cryptography. That's fine. But I will not advocate for more complexity to be shoved into age. It's fine as it is today.