Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Nick Mathewson
On Wed, Nov 20, 2013 at 11:02 AM, Nick Mathewson wrote: > Hi, all! > > Here's Incidentally, the canonical location for proposals is the torspec repository. Since this email went out, I've applied some fixes to the proposal to fix up some mistakes in it, and more mistakes I made. The latest versi

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Paul Syverson
Thanks Esfandiar. I had to run off for an hour and inadevertently sent my message before I had finished composing it, leaving a munged impression. My intended point was that the whole story has quite a bit to it beyond simply tweaking MQV. As you noted, that story has even more to it than what I s

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Esfandiar Mohammadi
Am 20.11.2013 um 18:19 schrieb Paul Syverson : > These authors found a > vulnerability in that protocol, improved on it, and proved their > protocol secure. Actually, Ian Goldberg, Douglas Stebila, and Berkant Ustaoglu found the vulnerability in Lasse and Paul's protocol [1], improved it, and pr

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Paul Syverson
On Wed, Nov 20, 2013 at 08:36:30AM -0800, Watson Ladd wrote: > Is it just me, or is this protocol MQV with the client generating a > fake long term key? Well yeah sort of, but the "details" are crucial. In "Improving efficiency and simplicity of Tor circuit establishment and hidden services" (avai

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Watson Ladd
Is it just me, or is this protocol MQV with the client generating a fake long term key? Sincerely, Watson Ladd ___ tor-dev mailing list tor-dev@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev

[tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Nick Mathewson
Hi, all! Here's Esfandiar Mohammadi's proposal for the Ace handshake. It should have been added as a numbered proposal back in July; I think I lost track of everything while the dev meeting was happening. Please let me know if you have more proposals that should be assigned numbers but haven't go