OpenPGP has excellent recovery properties out of the box BTW...
OpenPGP has excellent recovery properties out of the box BTW...
Yes, this is an excellent example of where this behaviour is suboptimal. We should not cargo cult authenticated encryption. It has its place but this isn't it.
> Any error you accept is malleability conceded to an attacker.
Sure, but malleability that has a close to zero chance of being a problem. We are talking about static encryption here. You only get one chance at malleability and the user immediately knows something has gone wrong:
gpg: WARNING: encrypted message has been manipulated!
>Are you complaining that age isn't malleable enough?Merely pointing out that for the most common use case age is objectively worse than GPG.
The logic you're applying here about how GPG can warn you if it has employed "recovery properties" to correct "single bit errors" was embraced enthusiastically by the Ruhr team to perform data recovery on other people's PGP-encrypted email messages.
https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt...
This isn't even a controversy among cryptographers or cryptography engineers.
Contrast the Efail situation with that of TLS. TLS allows almost unlimited secret trials against its cryptography by an attacker. There have been multiple practical attacks based on such oracles in TLS.
>This isn't even a controversy among cryptographers or cryptography engineers.
I would like to think that there were such people out there that understood that different techniques are applicable to different problems.
You probably know how that worked out for the Enigma.
Plain text attacks come in distinct categories. The block ciphers used in OpenPGP are generally considered to be immune to the sort of plain text attacks used against Enigma.
As described in Efail, they don’t need to guess; they know the first 11 bytes with very, very high probability.
I doubt me being able to read a third of your encrypted emails is remotely acceptable to you.
> The recipient […] would see the attack message and would immediately know there was something going on.
That solace is fleeting when it is already too late. The attacker has your decrypted message.
At any rate, none of this is something that anyone would accept from any modern cryptosystem, and the fact that PGP has you so backfooted that you'd feel the need to defend PGP's behavior here is a telling indication. "PGP: it's fine, as long as you don't use it to encrypt password reset emails. But for other emails it's fine, as long as the first 11 bytes of the email aren't guessable." Ok. Good note!
Maybe we should just put 128-bit nonces at the tops of all our emails. That just seems like common sense good engineering practice.
The paper did not provide any example of an email client where this would work. I have as of yet not been able to reproduce this. Since there would be no practical reason for such behaviour the assertion requires some sort of proof.
If I run a file through age, and then run that through a Reed-Solomon encoder, I now have a file that can be decoded even with single bit errors. But I think I also still have authenticated encryption. The cost is that my file takes a bit of extra space.
Am I missing something?
What's crazy about this is that you can get error correction without using insecure 1990s cryptography, simply by forward error correcting your ciphertext. I'm really having a hard time even getting my head around the argument you've managed to devise here.
[1] https://datatracker.ietf.org/doc/html/rfc4880#section-13.9
[2] https://articles.59.ca/doku.php?id=pgpfan:agevspgp#encrypted...