On Sun, Aug 23, 2015 at 7:28 PM, David Mazieres
<dm-list-tcpcr...@scs.stanford.edu> wrote:
> Watson Ladd <watsonbl...@gmail.com> writes:
>
>> Suppose everyone behaves the way you suggest. How unhappy are they
>> with using X or Y? Clearly not very much: they were willing to use it
>> if the other side didn't want their preference.
>
> Actually, people have *very* strong opinions about crypto and are
> willing to lobby pretty hard for particular algorithms and protocols.
> We should ensure such lobbying is directed towards OS vendors *after*
> TCP-ENO is standardized, not towards the working group beforehand (where
> it will further slow us down undermine TCP-ENO's goal of breaking the
> working group deadlock).

Who are people? Certainly not the people willing to use the
alternative algorithm if they have to. The problem is with the
existence of sites where only one algorithm must be used, and the OS
is configured accordingly.
>
>> The result of wanting to support every possible combination of
>> preferences and admin interface is having dead options linger forever
>> as the sysadmins keep copypasta in config files alive forever. I'd
>> rather order my crypto from McSorley's.
>
> The fact that we have way too many encryption options floating around
> does not mean all ciphersuites can be strictly ordered by security, for
> the simple reason that nobody can predict the future.  Cryptanalysis may
> alter the relative security of different algorithms at any time.  Or
> some NIST scandal might erupt casting doubt on the design methodology of
> P-512 compared to the nominally weaker Curve25519.  At such points, OS
> vendors need the ability to re-prioritize cipher suites without breaking
> backwards compatibility.

Am I proposing a fixed, static ordering? No. I'm proposing that in
response to cryptanalysis we have a functional migration plan, and the
negotiation mechanism to support it. We start with version 1, when
that becomes untenable move to version 2. This has eliminated SSHv1
from the Internet. The alternative plan has never eliminated any
cipher completely.

>
> David



-- 
"Man is born free, but everywhere he is in chains".
--Rousseau.

_______________________________________________
Tcpinc mailing list
Tcpinc@ietf.org
https://www.ietf.org/mailman/listinfo/tcpinc

Reply via email to