3 ms·
I know quite literally nothing about this situation, but I will offer one comment, which may or may not even be relevant. The security community are right to b
by fieldcny 3y ago
I know quite literally nothing about this situation, but I will offer one comment, which may or may not even be relevant.
The security community are right to be skeptical of changes such as this, the NSA has shown time and time again to have influenced design and standardization processes for their own benefit, it’s always been under the premise of “oh this makes things more secure” and it does superficially, then a decade later someone figures out we got had, again.
So standards are great, security standards are important, but the freedom to be skeptical about why and who are driving changes and just going your own way until it’s clear, that’s paramount.
- twiss 3y agoNIST is not the same organization as the NSA, though. And GCM was not designed by either - it was merely submitted to NIST as a proposal, which was accepted. It has been widely scrutinized, and there's a security proof available, which is more than can be said for CFB+MDC mode. So - of course everyone should feel free to be skeptical, but ideally one should be equally skeptical about the status quo and new proposals :)
- wahern 3y ago> which is more than can be said for CFB+MDC mode That seems like a red herring, at least if taken out of the context of this thread. OCB mode is already supported by GnuPG and had been added to the draft RFC before GCM was added. Werner has argued that there should only be a single AEAD mode, OCB, to simplify everything, including interoperability. But-for patent issues, GCM likely never would have existed; OCB is at least as secure, simpler, and substantially more performant. If one of OCB, GCM, or EAX turns out to be meaningfully less secure than the others, it's unlikely to be OCB.
- twiss 3y agoWell - sure, but we can't change the history, and GCM is the mode that got picked by NIST, is most widely implemented, and is used in lots of places. It has been widely analyzed and scrutinized, and is unlikely to turn out to be insecure at this point. I personally actually also agree that having a single mode would've been more elegant, but sometimes, in a collaborative open standard, compromises are necessary for practical or political reasons. Some people care about FIPS compliance, others care about performance, and so on. If you have a benevolent dictator, you can just tell (some of) those people to go away, but that's not really how an IETF working group works - the goal there is (rough) consensus. And, personally I don't think any of these compromises are so unreasonable as to call for fearmongering and references to the NSA. Again, GCM is used securely in lots of places, there's no reason it can't be used securely in OpenPGP too.