[JIRA] (OSJ-355) ConcatKDF parameter requirements too restrictive in ECDH
Scott Cantor (Jira)
jira at shibboleth.atlassian.net
Tue Jun 28 14:31:30 UTC 2022
Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) *commented* on OSJ-355 ( https://shibboleth.atlassian.net/browse/OSJ-355?atlOrigin=eyJpIjoiMjA1Yjk0ZTNmN2NhNGM5NDk2ZGY1NjMxNTExNDU3NjQiLCJwIjoiaiJ9 )
Re: ConcatKDF parameter requirements too restrictive in ECDH ( https://shibboleth.atlassian.net/browse/OSJ-355?atlOrigin=eyJpIjoiMjA1Yjk0ZTNmN2NhNGM5NDk2ZGY1NjMxNTExNDU3NjQiLCJwIjoiaiJ9 )
It may well make sense in this particular case (I really don’t know, it’s for Brent to review) but as a general matter…I really reject Postel’s “Law” completely and I especially reject it when it comes to security code. Being liberal in message handling is how you get bugs and security holes that live for 40 years because “compatibility”.
In this case, I’d be somewhat concerned about implementing some sort of “wrong” interpretation simply to be compatible with somebody else’s bug, if that’s what we’re dealing with.
OTOH, the XML Encryption spec is full of errors like this in how it accomodated certain algorithms defined by others, so I am not at all saying you’re wrong or that there wasn’t just a mistake made in the document.
Basically I think we’d want to fix this if it’s really an error, but not so much if it’s just a bug in some other codebase that we’re not accomodating, even if that bug was caused by an error in the spec. If the spec’s wrong, it’s wrong. We shouldn’t propagate that mistake by accepting inputs that follow it. That’s not a positive thing to do, and Postel was wrong about that IMHO.
( https://shibboleth.atlassian.net/browse/OSJ-355#add-comment?atlOrigin=eyJpIjoiMjA1Yjk0ZTNmN2NhNGM5NDk2ZGY1NjMxNTExNDU3NjQiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/OSJ-355#add-comment?atlOrigin=eyJpIjoiMjA1Yjk0ZTNmN2NhNGM5NDk2ZGY1NjMxNTExNDU3NjQiLCJwIjoiaiJ9 )
Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100201- sha1:66eda1f )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9012b1e7/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-a8a88988-7447-4c8d-bd71-9440713d5729
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9012b1e7/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-115b6139-5831-4caa-8143-9f57fec23972
Type: image/png
Size: 425 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9012b1e7/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-275ac958-7db6-4bd5-aeba-0b525894d13d
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9012b1e7/attachment-0005.png>
More information about the commits
mailing list