unencrypted assertions not working

Ian Young ian at iay.org.uk
Fri Apr 5 10:45:49 EDT 2013


On 3 Apr 2013, at 15:50, Tom Scavo <trscavo at gmail.com> wrote:

> message-level encryption […] benefits are quickly fading

The benefit of message-level encryption is that messages can be concealed from untrusted intermediaries.  The browser is the most obvious one, but delegation is another use case.  These are properties we need, and the requirement is not going away.  These benefits are simply not provided by point-to-point transport security on the front channel.

What has happened is that there are now some attacks against XML encryption when used with the currently deployed encryption methods.  At a theoretical level, XML encryption with these algorithms is "broken".  Whether those attacks are practical is a different question, but I think "quickly fading" is overstating the case even if you mean the *effectiveness* of currently deployed message-level encryption and not the *benefits*.  In my opinion, there is still substantial value in message-level encryption even with the known attacks; using "the benefits are quickly fading" as an excuse to stop bothering would be a mistake.

What happens when we find the algorithms we're using are weaker than we thought is that we step up to better algorithms, not abandon the thing we were trying to do.  In this case, we already have new algorithms; the issue is that some platform providers have been very reticent about making them available.  Today, for example, only about 1.5% of the service providers in the UK federation support GCM.  I'd expect that to improve a lot once the platform providers start shipping GCM support (e.g., with RHEL 7), and once we have that and IdP V3 then we're potentially back to the status quo ante in terms of XML encryption's effectiveness.

I'd summarise by saying:

* XML encryption is still worth using

* The reduced effectiveness of XML encryption for message-level security isn't an inevitable monotonic trend to zero.  Things will get better again, at least for people running the kind of software that actually pays attention to these things.  There will probably always be vendors who don't support things like GCM, in the same way that there are vendors today who don't support message level encryption at all.

* I encourage people not to abandon the mechanism in the meantime

	-- Ian



-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20130405/51f32e6b/attachment-0001.bin 


More information about the users mailing list