A few comments on ‘age’
neilmadden.blog
neilmadden.blog
That entirely works.Any sort of realistic crypto standard is going to have to support older systems right up to the point where any problems with those systems actually reduce security in some way. To do otherwise would be irresponsible to your users.
https://neilmadden.blog/2018/11/14/public-key-authenticated-...
https://groups.google.com/d/msgid/age-dev/505e74e5-1385-4055...
tl;dr: we seem to disagree on what users should want from age—confidentiality or also authentication—and that would lead not only to different design choices, but to drastically different UXs.
> ”Unfortunately, the age spec doesn’t document its threat model or the security goals it is intended to achieve ... Most importantly, the spec should define its security goals.”
I'm not sure what the corresponding version of the first issue would be in age, and then why the answer wouldn't be for age to make sure to check the entire header against a whitelist instead of considering just a subset of it.
Wouldn't you just need a tool that only outputs chunks after they're verified, and then you pipe that tool's output to age?
I'm not sure that signify or minisign currently support this streaming operation though.
You also need to be careful about what you think this tells you. For example, suppose you ran a competition where the winner is the first person to upload an encrypted+signed correct answer to a shared folder. An attacker can wait for somebody to upload the winning answer and then simply strip the real winner’s signature off and sign the encrypted blob (which they can’t decrypt) with their own private key - hurray, the attacker has now won the prize!
If you reverse the order of signing and encryption you can run into bugs like [1].
You can securely combine public key encryption and signatures by including extra metadata fields inside each layer. Or you can use a function that provides public key authenticated encryption like NaCl’s crypto_box or the mode I’ve proposed for JOSE [2].
[1]: https://groups.google.com/forum/m/#!msg/sci.crypt/73yb5a9pz2... [2]: https://tools.ietf.org/html/draft-madden-jose-ecdh-1pu-02
Edit: clarify ambiguous use of “their”