
From nobody Wed Jan 27 14:39:54 2016
Return-Path: <housley@vigilsec.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 342A01B2C2B for <smime@ietfa.amsl.com>; Wed, 27 Jan 2016 14:39:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BzJs1cjmEQn8 for <smime@ietfa.amsl.com>; Wed, 27 Jan 2016 14:39:52 -0800 (PST)
Received: from odin.smetech.net (x-bolt-wan.smeinc.net [209.135.219.146]) by ietfa.amsl.com (Postfix) with ESMTP id 877DE1B2C83 for <smime@ietf.org>; Wed, 27 Jan 2016 14:39:52 -0800 (PST)
Received: from localhost (unknown [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id C99969A4068 for <smime@ietf.org>; Wed, 27 Jan 2016 17:39:51 -0500 (EST)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id w41GUkwf4Cce for <smime@ietf.org>; Wed, 27 Jan 2016 17:38:35 -0500 (EST)
Received: from [192.168.2.104] (pool-108-51-128-219.washdc.fios.verizon.net [108.51.128.219]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id 84A649A4064 for <smime@ietf.org>; Wed, 27 Jan 2016 17:39:42 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Date: Wed, 27 Jan 2016 17:39:41 -0500
Message-Id: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
To: IETF SMIME <smime@ietf.org>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/8mZkNLJUwsh7h60SpFu3MigAlSg>
Subject: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Jan 2016 22:39:54 -0000

Take a look at this article: =
http://cryptosource.de/posts/smime_mta_en.html

Is there interest in updating the S/MIME specification to use =
authenticated-encryption?

Russ






From nobody Wed Jan 27 15:50:55 2016
Return-Path: <hallam@gmail.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C1A71A92AF for <smime@ietfa.amsl.com>; Wed, 27 Jan 2016 15:50:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.278
X-Spam-Level: 
X-Spam-Status: No, score=-1.278 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id an2GvDtJI2kN for <smime@ietfa.amsl.com>; Wed, 27 Jan 2016 15:50:53 -0800 (PST)
Received: from mail-lb0-x232.google.com (mail-lb0-x232.google.com [IPv6:2a00:1450:4010:c04::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CFACA1A1ADD for <smime@ietf.org>; Wed, 27 Jan 2016 15:50:52 -0800 (PST)
Received: by mail-lb0-x232.google.com with SMTP id x4so14704650lbm.0 for <smime@ietf.org>; Wed, 27 Jan 2016 15:50:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=yfdYl0p/FuPgLIJfZ8y/Y0zxZ6LxjSnxzFeVtjy7WIk=; b=I/OzWIrdpGZSTjE6b2qIa5Hnx1APFYH6GPfRbzKA7odIuYYYlMC6ounkgSn400kNjr 9FfCHpumn6Dt6KPTRxx9+iiLxSawMu0w93D19MDcy4rk8qITcu9OeAP8JdrLKo1tomNj WE6JCnvs7fe91AUVwkHZkqwPUH8AkXF6Atr2mQOs12r2vZvDorzVTivKjnncl9BY5+Ix tPhkUu79iRUxawWWMdClmvumfmeuWkUTPnTDJAmKxnh3Tp3EqlvS4ZBYokwAB+VuW5Y6 H+UWbGCFDEJ6947ESPAJRf/0XhOlwGljGv+fhcCbyKKAEIqK9W3HqbQUtZpb+sMA7U8R spJQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=yfdYl0p/FuPgLIJfZ8y/Y0zxZ6LxjSnxzFeVtjy7WIk=; b=GM/z86F/U4UMeitXDJq6p29LMxMgnXKeg0IWq4InCFfL9FxUBmS5m94b4j4Dx6XciT nmkXxbePBf/4LfHTBeN+R6YzQSbc+aI346ba4SAPfEvYP4pSOhw2pvMpMDB23agqQw3M 1t0pb1BWTQGIykhsOh3jyzm94lDTgA1F5+b+FrBlFlnj1FVCOu79vzhZqLCA4atow9d3 BnDZViXmJ7bp331nStdWrENiteMX8Lv5XMnin472VULbBofISkqQFawSjBzl+xJqlthT /VI1ZJXDXz+93mFXstgKlOBZ5Fsdh6qEbysQl+xXtblWociyxler9rPCdRickDb71iQs xb0g==
X-Gm-Message-State: AG10YOTo7JkPMReCRhhrJ9lGGVH4xbeL5UV1x9xjE//NGULI+VgslJiRC6eWng4J2HNM2HgdPkz6WgMUQO6JRQ==
MIME-Version: 1.0
X-Received: by 10.112.141.97 with SMTP id rn1mr2409lbb.80.1453938651040; Wed, 27 Jan 2016 15:50:51 -0800 (PST)
Sender: hallam@gmail.com
Received: by 10.112.1.33 with HTTP; Wed, 27 Jan 2016 15:50:50 -0800 (PST)
In-Reply-To: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
Date: Wed, 27 Jan 2016 18:50:50 -0500
X-Google-Sender-Auth: MYBa8My5izx8drUnkIVxDQ8XgVM
Message-ID: <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
To: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/6j011fFtWZ2I6WoVBNRheeFJfeg>
Cc: IETF SMIME <smime@ietf.org>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Jan 2016 23:50:54 -0000

On Wed, Jan 27, 2016 at 5:39 PM, Russ Housley <housley@vigilsec.com> wrote:
> Take a look at this article: http://cryptosource.de/posts/smime_mta_en.html
>
> Is there interest in updating the S/MIME specification to use authenticated-encryption?
>
> Russ

Is the attack limited to S/MIME or does it affect OpenPGP as well?


From nobody Thu Jan 28 07:03:44 2016
Return-Path: <tmiller@mitre.org>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA84B1A88A0 for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:03:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oEhEQFJo_g1C for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:03:40 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id 99C401A8899 for <smime@ietf.org>; Thu, 28 Jan 2016 07:03:39 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 02E4F6C065C; Thu, 28 Jan 2016 10:03:39 -0500 (EST)
Received: from imshyb01.MITRE.ORG (imshyb01.mitre.org [129.83.29.2]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id E07F86C0654; Thu, 28 Jan 2016 10:03:38 -0500 (EST)
Received: from imshyb01.MITRE.ORG (129.83.29.2) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1130.7; Thu, 28 Jan 2016 10:03:38 -0500
Received: from gcc01-dm2-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1130.7 via Frontend Transport; Thu, 28 Jan 2016 10:03:38 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mitre.onmicrosoft.com;  s=selector1-mitre-org; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=qf8rGi6bJGITW/TpzhmJuFEN+ADmmEK2/7BHsm/BKqs=; b=SgRrUpeDOyulyG6+qfOOfV6bFjW3Kuby6G7zcMIV8FKIo0vLQRLdxX/pqHo5w9uEXB+pTrF9173c8rjKQbPvWm8NCoWXK+fSg9LnV0Nsnc6SYe7iR/7dIqecMAXR1Bpm3mOki6QhkWRrSczA09LLTWWuQ5d1tQVdbrY1UI/ctEE=
Received: from BY1PR09MB0920.namprd09.prod.outlook.com (10.162.144.157) by BY1PR09MB0918.namprd09.prod.outlook.com (10.162.144.155) with Microsoft SMTP Server (TLS) id 15.1.390.13; Thu, 28 Jan 2016 15:02:37 +0000
Received: from BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) by BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) with mapi id 15.01.0390.016; Thu, 28 Jan 2016 15:02:37 +0000
From: "Miller, Timothy J." <tmiller@mitre.org>
To: Phillip Hallam-Baker <phill@hallambaker.com>, Russ Housley <housley@vigilsec.com>
Thread-Topic: [smime] Message takeover attacks against S/MIME
Thread-Index: AQHRWVOz4KNPhirNF06gk7JOdbn2s58QCHIAgAD7xcA=
Date: Thu, 28 Jan 2016 15:02:37 +0000
Message-ID: <BY1PR09MB0920F01A75E7AA89ABAFEE4AAEDA0@BY1PR09MB0920.namprd09.prod.outlook.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com>
In-Reply-To: <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=tmiller@mitre.org; 
x-originating-ip: [192.160.51.89]
x-microsoft-exchange-diagnostics: 1; BY1PR09MB0918; 5:nEQQjOzjruVoFNjCqruagjgR8a7FNrgTLBMg2z7BLwlk9DkINmIRIvgZGrBFOFlVoOqcKaOVj1K+4IIqJqu+kFA/G1TO4MzesQJ4vl5WWPJxx1uYwC/0tTinfwOIIT8bZa6dVkhwprGp4n8mK8hOlQ==; 24:BZZVv+s78fjjpJ52IIeAH2tf9PNdiUNw4tq82zmgtaswrvoqTerVu8crYQsJrY5lI2xDzUY4qeQlGLmhMa4To1rCMU0MrQFmJZ5uQ0mFKrA=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY1PR09MB0918;
x-ms-office365-filtering-correlation-id: 85c3cbc9-a070-4b8b-66de-08d327f40f5d
x-microsoft-antispam-prvs: <BY1PR09MB09182EE0D2AD4201A7552A42AEDA0@BY1PR09MB0918.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046); SRVR:BY1PR09MB0918; BCL:0; PCL:0; RULEID:; SRVR:BY1PR09MB0918; 
x-forefront-prvs: 083526BF8A
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(189002)(199003)(11100500001)(33656002)(5008740100001)(101416001)(3660700001)(1220700001)(5003600100002)(3470700001)(3846002)(102836003)(6116002)(40100003)(1096002)(92566002)(586003)(3280700002)(4326007)(122556002)(74316001)(2906002)(76576001)(54356999)(76176999)(50986999)(5001770100001)(97736004)(81156007)(87936001)(5002640100001)(5001960100002)(10400500002)(2900100001)(99286002)(86362001)(106356001)(2950100001)(106116001)(189998001)(105586002)(66066001)(77096005)(5004730100002); DIR:OUT; SFP:1101; SCL:1; SRVR:BY1PR09MB0918; H:BY1PR09MB0920.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: mitre.org does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Jan 2016 15:02:37.1717 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR09MB0918
X-OriginatorOrg: mitre.org
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/iBzBF6iJl_riGcBb3JOS2RTcBXw>
Cc: IETF SMIME <smime@ietf.org>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jan 2016 15:03:42 -0000

If I'm reading this right, the attack converts a signed-then-encrypted mess=
age into encrypted-then-signed by exploiting the use of CBC mode.  The atta=
cker deletes, moves, or alters encrypted message blocks (excepting blocks w=
ith pad bits) such that most of the message still decrypts into readable te=
xt but the inner signature breaks.  Then he applies his own outer signature=
. =20

Because the S/MIME spec requires clients to accept both types of messages a=
nd parsing of structures is lax, the recipient will accept the altered mess=
age.  If the recipient replies, he often will include the original message =
content as a quoted section, and confidentiality is lost.

OpenPGP forbids encrypt-then-sign (no format for it), so it's not vulnerabl=
e.

-- T



From nobody Thu Jan 28 07:04:45 2016
Return-Path: <tmiller@mitre.org>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F0DD61A88C0 for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:04:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OGSeETLMltIW for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:04:35 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id ACD951A88B4 for <smime@ietf.org>; Thu, 28 Jan 2016 07:04:34 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 63EB46C063A; Thu, 28 Jan 2016 10:04:34 -0500 (EST)
Received: from imshyb02.MITRE.ORG (imshyb02.mitre.org [129.83.29.3]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id 575596C043D; Thu, 28 Jan 2016 10:04:34 -0500 (EST)
Received: from imshyb01.MITRE.ORG (129.83.29.2) by imshyb02.MITRE.ORG (129.83.29.3) with Microsoft SMTP Server (TLS) id 15.0.1130.7; Thu, 28 Jan 2016 10:04:34 -0500
Received: from gcc01-dm2-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1130.7 via Frontend Transport; Thu, 28 Jan 2016 10:04:34 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mitre.onmicrosoft.com;  s=selector1-mitre-org; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=MYwkKtXmwX/b8Xy+YEE+nyWzX+HHUeH4zDKvPE34Jzg=; b=wwXtyjiY2kgVJxi4fuTfoXt3lyJpjlbMto1Ve72avJ8k7uQWBSNw83CEWu/OvJ1cetW5/Zm5xnkl0ElTNdVQ5YFFNnWJdF3j7RH1yjeLGmu1wE5xjlm8ahuORmGqOX6NVTABp3FfW98Iz/DUV2f3IKfwCo18y/Oxa0rIzpWX4xA=
Received: from BY1PR09MB0920.namprd09.prod.outlook.com (10.162.144.157) by BY1PR09MB0918.namprd09.prod.outlook.com (10.162.144.155) with Microsoft SMTP Server (TLS) id 15.1.390.13; Thu, 28 Jan 2016 15:04:32 +0000
Received: from BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) by BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) with mapi id 15.01.0390.016; Thu, 28 Jan 2016 15:04:33 +0000
From: "Miller, Timothy J." <tmiller@mitre.org>
To: Russ Housley <housley@vigilsec.com>, IETF SMIME <smime@ietf.org>
Thread-Topic: [smime] Message takeover attacks against S/MIME
Thread-Index: AQHRWVOz4KNPhirNF06gk7JOdbn2s58RB1Yg
Date: Thu, 28 Jan 2016 15:04:33 +0000
Message-ID: <BY1PR09MB0920DE9674BF17C4955D88F4AEDA0@BY1PR09MB0920.namprd09.prod.outlook.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
In-Reply-To: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=tmiller@mitre.org; 
x-originating-ip: [192.160.51.89]
x-microsoft-exchange-diagnostics: 1; BY1PR09MB0918; 5:I8A/loGX3H78lRGnQ675DnSB2mbmMYADNFP+L1+/2icuQE+G8rwg4qQVrWpt0UD8jEhyZ2CIJn+yK5KijqQLldm1MiPg+sD0zrAmvemiN08hpiNOog44/lTAnbgawgFnD9xsljhFVjSjXMh+d+Sj6A==; 24:F/pnsj0z3369+w0P8mDwpNsjtkVW+h/L3K+tgoHROYqof4sttiuaMcqFKxeibWmXiIO1BIODxbuYtMeK63Jy/grngixNaZaFUCTSdPDX+3U=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY1PR09MB0918;
x-ms-office365-filtering-correlation-id: b75f6e38-ee69-4974-bd8f-08d327f45465
x-microsoft-antispam-prvs: <BY1PR09MB0918EEADDC22BD0364F9D696AEDA0@BY1PR09MB0918.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001); SRVR:BY1PR09MB0918; BCL:0; PCL:0; RULEID:; SRVR:BY1PR09MB0918; 
x-forefront-prvs: 083526BF8A
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(189002)(199003)(558084003)(33656002)(5008740100001)(101416001)(3660700001)(1220700001)(5003600100002)(3470700001)(3846002)(102836003)(6116002)(40100003)(1096002)(92566002)(586003)(3280700002)(122556002)(74316001)(2906002)(76576001)(54356999)(76176999)(50986999)(107886002)(5001770100001)(97736004)(81156007)(87936001)(5002640100001)(5001960100002)(10400500002)(2900100001)(99286002)(86362001)(106356001)(2950100001)(106116001)(189998001)(105586002)(66066001)(77096005)(5004730100002); DIR:OUT; SFP:1101; SCL:1; SRVR:BY1PR09MB0918; H:BY1PR09MB0920.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: mitre.org does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Jan 2016 15:04:33.0360 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR09MB0918
X-OriginatorOrg: mitre.org
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/My3JKL0jlY2_jXuqjqQr5KnS0u0>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jan 2016 15:04:39 -0000

> Is there interest in updating the S/MIME specification to use authenticat=
ed-
> encryption?

Seems like it would be a straightforward update.

-- T


From lijun.liao@gmail.com  Thu Jan 28 02:02:54 2016
Return-Path: <lijun.liao@gmail.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41C3F1B339D for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 02:02:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HHuyJVziicPW for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 02:02:53 -0800 (PST)
Received: from mail-wm0-x22a.google.com (mail-wm0-x22a.google.com [IPv6:2a00:1450:400c:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BA19B1A86F0 for <smime@ietf.org>; Thu, 28 Jan 2016 02:02:52 -0800 (PST)
Received: by mail-wm0-x22a.google.com with SMTP id 128so3113921wmz.1 for <smime@ietf.org>; Thu, 28 Jan 2016 02:02:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:content-type; bh=JHadM01d0+ChndiWcC+VVZg/cX6j/f2BSWBiSWrKNtY=; b=LEOyrww6AbQui1j724G1ZW4ra/V66RofbecBBxnqXaxUUPTiUPKdUZuA+w69KR4334 Z6fG7bs/KsP645LNcnxe1au1lM3nnfyMNYE1SyMBy2Xu87CSPcJ0ILQlu1O/uBIplk6z IIJOJCpIm0iAFQALzZNrjLL+iAXeIm+3x1Obf1RXB5Enn/UzpD0zokV3AcrqJcTW37hy dKFP7Vfl0No4uvmVpPhKybq4sjkp3espy3qqIlafVstdnJVM/HAKNCfLw0DGGYMwWJMH Np2MmgiB7tm1eA4ZOLeylHmw8FyLl+xXqEBvAQedbXrdr+N4A4oaA68H13AabDFQJATL vd2w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:date :message-id:subject:from:to:content-type; bh=JHadM01d0+ChndiWcC+VVZg/cX6j/f2BSWBiSWrKNtY=; b=jYCXwkSge49v3EbiBNvoy+Z9UbHtTiCp//iyNnUpgfNG4ww29lzY8ak4wwzDArpDh0 LuObia2lwEkHclAMg6yjRIdRUTJ7jSSZpAWX5Asvqau77JDBNRQdnvg0quHN5TbNe9Qd ihbgmLk6d40+jiQiFbpion26I3CI9+KGlsTfY2hsS9l7jhlyfJN+mQyxr14bT56nKMjE dklHyXL0eoZzl0lGEfmGOKsyLadGcUdhRFxLE8IeJlUDMmWXSlopWEqGSSD4gSN0u1XK kzmC/TD5WpvEWUX6OLcTMfj9IeoTgQfunt+qyJd7c72esTxULUk/Y23HN+WwHF3gLtH3 xHSQ==
X-Gm-Message-State: AG10YOQw9ONfrOKB6sfXcG8M2rSAdSSzz+Zdr0mu0XG9SXaumA/FwMxBhO0AGKL97rDpA2Fc/Xs/rlV2jO51UA==
MIME-Version: 1.0
X-Received: by 10.28.111.217 with SMTP id c86mr1954147wmi.31.1453975371397; Thu, 28 Jan 2016 02:02:51 -0800 (PST)
Sender: lijun.liao@gmail.com
Received: by 10.27.23.80 with HTTP; Thu, 28 Jan 2016 02:02:51 -0800 (PST)
In-Reply-To: <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com>
Date: Thu, 28 Jan 2016 11:02:51 +0100
X-Google-Sender-Auth: MZirc6vF0qsObCkYDIv6AGr1PWg
Message-ID: <CANNx7D8az36-BD6ZU4GraHdGfNJa=OEoDVKj16X1S_GSDPEaYA@mail.gmail.com>
From: Lijun Liao <lijun.liao@rub.de>
To: IETF SMIME <smime@ietf.org>
Content-Type: multipart/alternative; boundary=001a11470616864356052a620589
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/n1cXFW2YLunUiyLr6wSMuZ7a9hc>
X-Mailman-Approved-At: Thu, 28 Jan 2016 07:41:36 -0800
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jan 2016 10:05:38 -0000

--001a11470616864356052a620589
Content-Type: text/plain; charset=UTF-8

Indeed there are much simple ways to get the encrypted messages by adding
some header fields like Reply-To, Sender, To, CC, etc. Since these header
fields are not cryptographically protected by the signature and encryption,
the recipient mail client is not able to detect the modification. If she
answers the email, a copy will be delivered to the attacker.

Sure the aforementioned attack can be HINDERED by the inline message type
message/rfc822 introducted in S/MIME v3.1. I use here the word HINDER
instead of PREVENT due to the fact that the specification does not prevent
the recipient client from using the outer header fields which are not
protected. By the way, not all of email clients (indeed I know none) can be
configured to accept only intern message/rfc822 type.

Lijun Liao

--001a11470616864356052a620589
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div>Indeed there are much simple ways to get th=
e encrypted messages by adding some header fields like Reply-To, Sender, To=
, CC, etc. Since these header fields are not cryptographically protected by=
 the signature and encryption, the recipient mail client is not able to det=
ect the modification. If she answers the email, a copy will be delivered to=
 the attacker.<br><br></div><div>Sure the aforementioned attack can be HIND=
ERED by the inline message type message/rfc822 introducted in S/MIME v3.1. =
I use here the word HINDER instead of PREVENT due to the fact that the spec=
ification does not prevent the recipient client from using the outer header=
 fields which are not protected. By the way, not all of email clients (inde=
ed I know none) can be configured to accept only intern message/rfc822 type=
.<br></div><div><br></div><div>Lijun Liao<br></div></div></div></div>

--001a11470616864356052a620589--


From nobody Thu Jan 28 07:47:37 2016
Return-Path: <housley@vigilsec.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1043F1A8F3F for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:47:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ntaiOsYXCBbr for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 07:47:34 -0800 (PST)
Received: from odin.smetech.net (x-bolt-wan.smeinc.net [209.135.219.146]) by ietfa.amsl.com (Postfix) with ESMTP id 62CB61A8BB2 for <smime@ietf.org>; Thu, 28 Jan 2016 07:47:34 -0800 (PST)
Received: from localhost (unknown [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id 37A42F9CEBB for <smime@ietf.org>; Thu, 28 Jan 2016 10:47:22 -0500 (EST)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id I75I-pWe-i-t for <smime@ietf.org>; Thu, 28 Jan 2016 10:46:14 -0500 (EST)
Received: from [192.168.2.104] (pool-108-51-128-219.washdc.fios.verizon.net [108.51.128.219]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id C574FF9C2AA for <smime@ietf.org>; Thu, 28 Jan 2016 10:47:21 -0500 (EST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Apple Message framework v1085)
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <CANNx7D8az36-BD6ZU4GraHdGfNJa=OEoDVKj16X1S_GSDPEaYA@mail.gmail.com>
Date: Thu, 28 Jan 2016 10:47:21 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <CE980BB7-1ABE-4014-A112-469DC9D71FE7@vigilsec.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com> <CANNx7D8az36-BD6ZU4GraHdGfNJa=OEoDVKj16X1S_GSDPEaYA@mail.gmail.com>
To: IETF SMIME <smime@ietf.org>
X-Mailer: Apple Mail (2.1085)
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/ZkAZYW1g8RZ__tWJ4I7Pm7arOFk>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jan 2016 15:47:36 -0000

I do not know of any user agents that can be configured to accept only =
intern message/rfc822 type, or even flag the difference to the user.  =
Most users would not understand the flag if it was there.

I would like to know if there is enough energy to work on a re-charter =
for the SMIME working group and then produce an updated specification.  =
If there is enough interest, Stephen Farrell is willing to sponsor the =
charter.

I am willing to work on it.

Russ


On Jan 28, 2016, at 5:02 AM, Lijun Liao wrote:

> Indeed there are much simple ways to get the encrypted messages by =
adding some header fields like Reply-To, Sender, To, CC, etc. Since =
these header fields are not cryptographically protected by the signature =
and encryption, the recipient mail client is not able to detect the =
modification. If she answers the email, a copy will be delivered to the =
attacker.
>=20
> Sure the aforementioned attack can be HINDERED by the inline message =
type message/rfc822 introducted in S/MIME v3.1. I use here the word =
HINDER instead of PREVENT due to the fact that the specification does =
not prevent the recipient client from using the outer header fields =
which are not protected. By the way, not all of email clients (indeed I =
know none) can be configured to accept only intern message/rfc822 type.
>=20
> Lijun Liao


From nobody Thu Jan 28 08:41:08 2016
Return-Path: <ietf@augustcellars.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A8E681B2DB9 for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 08:41:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0rQVmmPFLFGQ for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 08:41:05 -0800 (PST)
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1C1231B2DB8 for <smime@ietf.org>; Thu, 28 Jan 2016 08:41:04 -0800 (PST)
Received: from hebrews (ip-64-134-220-6.public.wayport.net [64.134.220.6]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp1.pacifier.net (Postfix) with ESMTPSA id 4C6DA2CA1B; Thu, 28 Jan 2016 08:41:04 -0800 (PST)
From: "Jim Schaad" <ietf@augustcellars.com>
To: "'Russ Housley'" <housley@vigilsec.com>, "'IETF SMIME'" <smime@ietf.org>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <CAMm+LwjFMmJe4vRK7rzw0DmqTx-Fr-ryaCUrKoV0kQESODusnA@mail.gmail.com> <CANNx7D8az36-BD6ZU4GraHdGfNJa=OEoDVKj16X1S_GSDPEaYA@mail.gmail.com> <CE980BB7-1ABE-4014-A112-469DC9D71FE7@vigilsec.com>
In-Reply-To: <CE980BB7-1ABE-4014-A112-469DC9D71FE7@vigilsec.com>
Date: Thu, 28 Jan 2016 08:38:28 -0800
Message-ID: <05a801d159ea$51ae6ce0$f50b46a0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 15.0
Content-Language: en-us
Thread-Index: AQKtp9I9legZyi+Zwpzy1sVu6LFd5gJe4Ne2AXeLBowCngywA50k4Rfw
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/we93zkCxsbdUfZ1yKoSGGUS-j6c>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jan 2016 16:41:06 -0000

I am more than willing to help with this.  I don't know if there will be any
industry pickup but I think it does need to be done.

Jim


> -----Original Message-----
> From: smime [mailto:smime-bounces@ietf.org] On Behalf Of Russ Housley
> Sent: Thursday, January 28, 2016 7:47 AM
> To: IETF SMIME <smime@ietf.org>
> Subject: Re: [smime] Message takeover attacks against S/MIME
> 
> I do not know of any user agents that can be configured to accept only
intern
> message/rfc822 type, or even flag the difference to the user.  Most users
would
> not understand the flag if it was there.
> 
> I would like to know if there is enough energy to work on a re-charter for
the
> SMIME working group and then produce an updated specification.  If there
is
> enough interest, Stephen Farrell is willing to sponsor the charter.
> 
> I am willing to work on it.
> 
> Russ
> 
> 
> On Jan 28, 2016, at 5:02 AM, Lijun Liao wrote:
> 
> > Indeed there are much simple ways to get the encrypted messages by
adding
> some header fields like Reply-To, Sender, To, CC, etc. Since these header
fields
> are not cryptographically protected by the signature and encryption, the
> recipient mail client is not able to detect the modification. If she
answers the
> email, a copy will be delivered to the attacker.
> >
> > Sure the aforementioned attack can be HINDERED by the inline message
type
> message/rfc822 introducted in S/MIME v3.1. I use here the word HINDER
> instead of PREVENT due to the fact that the specification does not prevent
the
> recipient client from using the outer header fields which are not
protected. By
> the way, not all of email clients (indeed I know none) can be configured
to
> accept only intern message/rfc822 type.
> >
> > Lijun Liao
> 
> _______________________________________________
> smime mailing list
> smime@ietf.org
> https://www.ietf.org/mailman/listinfo/smime


From nobody Thu Jan 28 20:37:23 2016
Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CED341B3D1D for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 20:37:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pMMh20-oOjJB for <smime@ietfa.amsl.com>; Thu, 28 Jan 2016 20:37:18 -0800 (PST)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0AADB1B3946 for <smime@ietf.org>; Thu, 28 Jan 2016 20:37:17 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1454042238; x=1485578238; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=rFlJ17ji3uyx5zc12x/C5r0a2kY2sn6ZquA6uCtCloU=; b=s1RD1ztDocBOSwrIqs80oJG05xRg9rwK0mq3Wy+R/0nJ9DVe/N98WCOf eTNkwt2KMalDqRYDsLsHWR1Jphn0IVAtpKqs00Q10ns4DkswkwQIKELGD um5guOJ0hm5vpAtxRPE7rNVpivNy9JatIX4vK2SxG3XsVJs4QX7WUoU1D CcFfwrUv5xWy8QwCX9gCVcssVZQ8pap8ftWFOWX4yoFwNvwoEwvr8Qv72 aWxpB2oR4t0UjaE7YIlCiQEsubTpElWxZ0zApOGPDZ0reXqxD3Sqpfh76 1jU62BG9fLWYLnRtBaKDX9L64F7CNEweF3b2XXibWL1w06+ixb8t6usE6 g==;
X-IronPort-AV: E=Sophos;i="5.22,361,1449486000"; d="scan'208";a="65361223"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 130.216.4.171 - Outgoing - Outgoing
Received: from exchangemx.uoa.auckland.ac.nz (HELO uxchange10-fe4.UoA.auckland.ac.nz) ([130.216.4.171]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 29 Jan 2016 17:37:16 +1300
Received: from UXCN10-5.UoA.auckland.ac.nz ([169.254.5.153]) by uxchange10-fe4.UoA.auckland.ac.nz ([169.254.109.63]) with mapi id 14.03.0266.001; Fri, 29 Jan 2016 17:37:16 +1300
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Russ Housley <housley@vigilsec.com>, IETF SMIME <smime@ietf.org>
Thread-Topic: [smime] Message takeover attacks against S/MIME
Thread-Index: AQHRWVPCOTHF8ZvedEeEGiWu4sojSZ8R6qkI
Date: Fri, 29 Jan 2016 04:37:15 +0000
Message-ID: <9A043F3CF02CD34C8E74AC1594475C73F4BDB8A8@uxcn10-5.UoA.auckland.ac.nz>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
In-Reply-To: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/0mK2wolWv9qk7QnMhpQu94OxMQQ>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jan 2016 04:37:21 -0000

Russ Housley <housley@vigilsec.com> writes:=0A=
=0A=
>Take a look at this article: http://cryptosource.de/posts/smime_mta_en.htm=
l=0A=
>=0A=
>Is there interest in updating the S/MIME specification to use authenticate=
d-=0A=
>encryption?=0A=
=0A=
It looks like a pretty contrived attack, you need to be able to truncate a=
=0A=
message, both at the start and end, on a 16-byte boundary to turn a signed=
=0A=
message into a plain, unsigned one, and still have the client accept the=0A=
result as a valid message.  They found one client that does that, but that=
=0A=
sounds more like a buggy client than a major problem (none of the others di=
d=0A=
it).=0A=
=0A=
In any case the fix should be pretty minimal, if anything is required at al=
l:=0A=
If the SMIMECaps in the cert you're encrypting for indicates authEnc, use=
=0A=
that.  My code already does that and possibly other impementations do too.=
=0A=
=0A=
Peter.=


From nobody Fri Jan 29 06:46:59 2016
Return-Path: <hallam@gmail.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E557B1A6F8E for <smime@ietfa.amsl.com>; Fri, 29 Jan 2016 06:46:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UN70nyw1l81g for <smime@ietfa.amsl.com>; Fri, 29 Jan 2016 06:46:55 -0800 (PST)
Received: from mail-pf0-x230.google.com (mail-pf0-x230.google.com [IPv6:2607:f8b0:400e:c00::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C254D1A6F93 for <smime@ietf.org>; Fri, 29 Jan 2016 06:46:55 -0800 (PST)
Received: by mail-pf0-x230.google.com with SMTP id n128so42971569pfn.3 for <smime@ietf.org>; Fri, 29 Jan 2016 06:46:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=sender:date:from:to:message-id:in-reply-to:references:subject :mime-version:content-type; bh=SA2PyFuRuCOI61BBg83HinHjeM3HRRsJ8864LNX4JYc=; b=l6KdXdycHqCslQ7RPz747g9OcwM7vrhL7cTTiZDmadjhoFo4UsCZvVhqpfBJTCGmLP oyRDfvY1BtSfSAipgqMEtfNc7pSuruoJzQr/BllZ8beAzoZhbT/biNm8Z390Rxh/kI30 jwrgy5dwfUWF+Xxh0a9h30mkvl9WB8Asq2ba/FDHShNF4JFT/Jst5zmZMz5Kx3S+Kuse xtHaKAlis6AhHeXqvUioLgxeDAxK2bPK6Bf/bFY3SO9Cq1Wd53R0BJaPQCIAl1nStM+l 7/lxX6KerUpSwWETbRCTCMoPE96yMhGYN2HsVO/2hLytdcLcS8pXZAW075ujQlnonlus bEmw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:sender:date:from:to:message-id:in-reply-to :references:subject:mime-version:content-type; bh=SA2PyFuRuCOI61BBg83HinHjeM3HRRsJ8864LNX4JYc=; b=BRaxH9thbg5CDvWB+CmngJE6oFe6emQJ0yAeIfAiw0tgsyaVOBnQ+KFcM6VlvFSXVO Si8r75/NcPZWmQR3pQpEQTKcCWB/dwLf9QA6vgJAgVsyIOWi6BXXqysIsg2rZm9FB4o/ 7AQCMacC5L2XFS2bcQn7G82K3QzXgtmkDt8tkuhf1t0bWZ0WOMwckNHE21ajQIEULnY1 Zd/y1ad7kS2kOubkdH4rB+3LOgMmzMDbVi9fchFul1H9e1eVBt2Yb0alFiW04/FQhl6S ddb2guzHbFx7Q0dr/AEuD4aUo0o+0Z2SSFCMfRAbkgZnwytYFpN6ZJVr3kjHk8fGeaSP EUpg==
X-Gm-Message-State: AG10YOTAhYAIHoW62qglrgtxcDAFKzPkXlW5wcTuXJefo0zjMDC8k1a8uXN09OzSLO2hYA==
X-Received: by 10.98.42.135 with SMTP id q129mr13746344pfq.13.1454078814999; Fri, 29 Jan 2016 06:46:54 -0800 (PST)
Received: from mail.outlook.com (ec2-52-24-139-88.us-west-2.compute.amazonaws.com. [52.24.139.88]) by smtp.gmail.com with ESMTPSA id p71sm24188384pfa.11.2016.01.29.06.46.51 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 29 Jan 2016 06:46:52 -0800 (PST)
Sender: Phillip Hallam-Baker <hallam@gmail.com>
Date: Fri, 29 Jan 2016 14:46:51 +0000 (UTC)
From: Phillip Hallam-Baker <phill@hallambaker.com>
To: Russ Housley <housley@vigilsec.com>, IETF SMIME <smime@ietf.org>,  Peter Gutmann <pgut001@cs.auckland.ac.nz>
Message-ID: <994C5976EA09B556.B83AD642-A6F0-486D-876C-D224454B8FAA@mail.outlook.com>
In-Reply-To: <9A043F3CF02CD34C8E74AC1594475C73F4BDB8A8@uxcn10-5.UoA.auckland.ac.nz>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <9A043F3CF02CD34C8E74AC1594475C73F4BDB8A8@uxcn10-5.UoA.auckland.ac.nz>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_60353_533400892.1454078811416"
X-Mailer: Outlook for iOS and Android
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/otoU4I-msWt35nnr2CquLNk-IaA>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jan 2016 14:46:59 -0000

------=_Part_60353_533400892.1454078811416
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

If the only thing we need to do is add AES-GCM, then the obvious venue is C=
URDLE.=C2=A0
But we do need to do something soon because S/MIME is loosing deployment su=
pport. It isn't in the new Microsoft platform mail system, it is virtually =
unusable in iOS, it is absent in the Android client and it takes 30 minutes=
 to configure Thuinderbird. That would not worry me if OpenPGP was filling =
the gap but it is not.
If we are going to get working end to end secure mail, several things have =
to happen:
1) Stop the S/MIME vs OpenPGP standards battle. The GNU code and most of th=
e other libraries for OpenPGP support S/MIME. They have to do PKIX for SMTP=
 STARTLS, S/MIME is a minor extra burden.
The choice of message infrastructure should not determine the choice of the=
 trust infrastructure. It is not possible to solve every trust problem with=
 either PKIX or Web of Trust or direct trust via fingerprints.
2) We have to have up to date specifications for the end-to-end message for=
mats that define a consistent modern crypto suite. [CURDLE]
3) We have to work out how to make end to end mail work properly with Web M=
ail=C2=A0
4) Configuration of the clients has to be absolutely painless. Which is wha=
t I designed the Mathematical Mesh to address. Use cryptography to solve th=
e problem of making computers easier to use.
I am just redoing my podcast demonstrating the Mesh, the sound on the first=
 one doesn't meet my standards.

If people want to look at what I have done and then do the same thing compl=
etely differently, that is fine with me as long as they do it, deploy it an=
d it works as well. But given that I am using a completely modern, fashiona=
ble set of standards (HTTP/1.1, JSON, JOSE, CURDLE) and none of this requir=
es a CA, I can't see it likely people would want to make that sort of chang=
e.
It does need review though. And deployment. The killer app for the Mesh can=
't be secure email because there isn't much value to a system that reaches =
0.1% of Internet users (combined user as of OpenPGP and S/MIME). But most p=
eople would like to have an easy, robust and really secure way to manage SS=
H keys, most people would like an easy way to encrypt their data in the clo=
ud and pretty much everyone is fed up with having to remember passwords for=
 100 web sites. All those benefits are immediate regardless of whether anyo=
ne else buys in.
The Mesh itself is an untrustworthy service, this is a completely end to en=
d protocol. The user is in direct and full control of all their data at all=
 times.

Sent from Outlook Mobile

    _____________________________
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
Sent: Thursday, January 28, 2016 11:37 PM
Subject: Re: [smime] Message takeover attacks against S/MIME
To: Russ Housley <housley@vigilsec.com>, IETF SMIME <smime@ietf.org>


Russ Housley <housley@vigilsec.com> writes:

>Take a look at this article: http://cryptosource.de/posts/smime_mta_en.htm=
l
>
>Is there interest in updating the S/MIME specification to use authenticate=
d-
>encryption?

It looks like a pretty contrived attack, you need to be able to truncate a
message, both at the start and end, on a 16-byte boundary to turn a signed
message into a plain, unsigned one, and still have the client accept the
result as a valid message.  They found one client that does that, but that
sounds more like a buggy client than a major problem (none of the others di=
d
it).

In any case the fix should be pretty minimal, if anything is required at al=
l:
If the SMIMECaps in the cert you're encrypting for indicates authEnc, use
that.  My code already does that and possibly other impementations do too.

Peter.
_______________________________________________
smime mailing list
smime@ietf.org
https://www.ietf.org/mailman/listinfo/smime



 =20
------=_Part_60353_533400892.1454078811416
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable


    <div id=3D"compose" contenteditable=3D"true" style=3D"padding-left: 20p=
x; padding-right: 20px; padding-bottom: 8px;"><div>If the only thing we nee=
d to do is add AES-GCM, then the obvious venue is CURDLE.&nbsp;</div><div><=
br></div><div>But we do need to do something soon because S/MIME is loosing=
 deployment support. It isn't in the new Microsoft platform mail system, it=
 is virtually unusable in iOS, it is absent in the Android client and it ta=
kes 30 minutes to configure Thuinderbird. That would not worry me if OpenPG=
P was filling the gap but it is not.</div><div><br></div><div>If we are goi=
ng to get working end to end secure mail, several things have to happen:</d=
iv><div><br></div><div>1) Stop the S/MIME vs OpenPGP standards battle. The =
GNU code and most of the other libraries for OpenPGP support S/MIME. They h=
ave to do PKIX for SMTP STARTLS, S/MIME is a minor extra burden.</div><div>=
<br></div><div>The choice of message infrastructure should not determine th=
e choice of the trust infrastructure. It is not possible to solve every tru=
st problem with either PKIX or Web of Trust or direct trust via fingerprint=
s.</div><div><br></div><div>2) We have to have up to date specifications fo=
r the end-to-end message formats that define a consistent modern crypto sui=
te. [CURDLE]</div><div><br></div><div>3) We have to work out how to make en=
d to end mail work properly with Web Mail&nbsp;</div><div><br></div><div>4)=
 Configuration of the clients has to be absolutely painless. Which is what =
I designed the Mathematical Mesh to address. Use cryptography to solve the =
problem of making computers easier to use.</div><div><br></div><div>I am ju=
st redoing my podcast demonstrating the Mesh, the sound on the first one do=
esn't meet my standards.</div><div><br></div><div><br></div><div>If people =
want to look at what I have done and then do the same thing completely diff=
erently, that is fine with me as long as they do it, deploy it and it works=
 as well. But given that I am using a completely modern, fashionable set of=
 standards (HTTP/1.1, JSON, JOSE, CURDLE) and none of this requires a CA, I=
 can't see it likely people would want to make that sort of change.</div><d=
iv><br></div><div>It does need review though. And deployment. The killer ap=
p for the Mesh can't be secure email because there isn't much value to a sy=
stem that reaches 0.1% of Internet users (combined user as of OpenPGP and S=
/MIME). But most people would like to have an easy, robust and really secur=
e way to manage SSH keys, most people would like an easy way to encrypt the=
ir data in the cloud and pretty much everyone is fed up with having to reme=
mber passwords for 100 web sites. All those benefits are immediate regardle=
ss of whether anyone else buys in.</div><div><br></div><div>The Mesh itself=
 is an untrustworthy service, this is a completely end to end protocol. The=
 user is in direct and full control of all their data at all times.</div><d=
iv><br><br><div class=3D"acompli_signature">Sent from <a href=3D"https://ak=
a.ms/sdimjr">Outlook Mobile</a></div><br></div></div>
    <div class=3D"gmail_quote">_____________________________<br>From: Peter=
 Gutmann &lt;<a dir=3D"ltr" href=3D"mailto:pgut001@cs.auckland.ac.nz" x-app=
le-data-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-dat=
a-detectors-result=3D"1">pgut001@cs.auckland.ac.nz</a>&gt;<br>Sent: Thursda=
y, January 28, 2016 11:37 PM<br>Subject: Re: [smime] Message takeover attac=
ks against S/MIME<br>To: Russ Housley &lt;<a dir=3D"ltr" href=3D"mailto:hou=
sley@vigilsec.com" x-apple-data-detectors=3D"true" x-apple-data-detectors-t=
ype=3D"link" x-apple-data-detectors-result=3D"3">housley@vigilsec.com</a>&g=
t;, IETF SMIME &lt;<a dir=3D"ltr" href=3D"mailto:smime@ietf.org" x-apple-da=
ta-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-data-det=
ectors-result=3D"4">smime@ietf.org</a>&gt;<br><br><br>Russ Housley &lt;<a d=
ir=3D"ltr" href=3D"mailto:housley@vigilsec.com" x-apple-data-detectors=3D"t=
rue" x-apple-data-detectors-type=3D"link" x-apple-data-detectors-result=3D"=
5">housley@vigilsec.com</a>&gt; writes:<br><br>&gt;Take a look at this arti=
cle: <a dir=3D"ltr" href=3D"http://cryptosource.de/posts/smime_mta_en.html"=
 x-apple-data-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-app=
le-data-detectors-result=3D"6">http://cryptosource.de/posts/smime_mta_en.ht=
ml</a><br>&gt;<br>&gt;Is there interest in updating the S/MIME specificatio=
n to use authenticated-<br>&gt;encryption?<br><br>It looks like a pretty co=
ntrived attack, you need to be able to truncate a<br>message, both at the s=
tart and end, on a 16-byte boundary to turn a signed<br>message into a plai=
n, unsigned one, and still have the client accept the<br>result as a valid =
message.  They found one client that does that, but that<br>sounds more lik=
e a buggy client than a major problem (none of the others did<br>it).<br><b=
r>In any case the fix should be pretty minimal, if anything is required at =
all:<br>If the SMIMECaps in the cert you're encrypting for indicates authEn=
c, use<br>that.  My code already does that and possibly other impementation=
s do too.<br><br>Peter.<br>_______________________________________________<=
br>smime mailing list<br><a dir=3D"ltr" href=3D"mailto:smime@ietf.org" x-ap=
ple-data-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-da=
ta-detectors-result=3D"7">smime@ietf.org</a><br><a dir=3D"ltr" href=3D"http=
s://www.ietf.org/mailman/listinfo/smime" x-apple-data-detectors=3D"true" x-=
apple-data-detectors-type=3D"link" x-apple-data-detectors-result=3D"8">http=
s://www.ietf.org/mailman/listinfo/smime</a><br><br><br></div>
 =20
------=_Part_60353_533400892.1454078811416--


From nobody Fri Jan 29 08:23:28 2016
Return-Path: <housley@vigilsec.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 298F51ACE3F for <smime@ietfa.amsl.com>; Fri, 29 Jan 2016 08:23:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MHNz7YLMIPRm for <smime@ietfa.amsl.com>; Fri, 29 Jan 2016 08:23:25 -0800 (PST)
Received: from odin.smetech.net (x-bolt-wan.smeinc.net [209.135.219.146]) by ietfa.amsl.com (Postfix) with ESMTP id 8F4A81AC3D1 for <smime@ietf.org>; Fri, 29 Jan 2016 08:23:25 -0800 (PST)
Received: from localhost (unknown [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id 6176A9A4013; Fri, 29 Jan 2016 11:23:25 -0500 (EST)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id POsB69v9TM-Y; Fri, 29 Jan 2016 11:22:17 -0500 (EST)
Received: from [10.85.3.71] (wsip-98-172-24-238.dc.dc.cox.net [98.172.24.238]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id EDA2C9A400C; Fri, 29 Jan 2016 11:23:24 -0500 (EST)
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <9A043F3CF02CD34C8E74AC1594475C73F4BDB8A8@uxcn10-5.UoA.auckland.ac.nz>
Date: Fri, 29 Jan 2016 11:23:24 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <D40EF58F-28D0-4A5B-85FD-515ADF73BDA8@vigilsec.com>
References: <B3640A5E-C644-4E53-8FDD-D7FBE87F300D@vigilsec.com> <9A043F3CF02CD34C8E74AC1594475C73F4BDB8A8@uxcn10-5.UoA.auckland.ac.nz>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
X-Mailer: Apple Mail (2.1085)
Archived-At: <http://mailarchive.ietf.org/arch/msg/smime/VpRpsHeJadMJoQnbampp6BwM3ew>
Cc: IETF SMIME <smime@ietf.org>
Subject: Re: [smime] Message takeover attacks against S/MIME
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jan 2016 16:23:27 -0000

Peter:

> Russ Housley <housley@vigilsec.com> writes:
>=20
>> Take a look at this article: =
http://cryptosource.de/posts/smime_mta_en.html
>>=20
>> Is there interest in updating the S/MIME specification to use =
authenticated-
>> encryption?
>=20
> It looks like a pretty contrived attack, you need to be able to =
truncate a
> message, both at the start and end, on a 16-byte boundary to turn a =
signed
> message into a plain, unsigned one, and still have the client accept =
the
> result as a valid message.  They found one client that does that, but =
that
> sounds more like a buggy client than a major problem (none of the =
others did
> it).
>=20
> In any case the fix should be pretty minimal, if anything is required =
at all:
> If the SMIMECaps in the cert you're encrypting for indicates authEnc, =
use
> that.  My code already does that and possibly other impementations do =
too.

CMS already supports Enveloped-Data and Authenticated-Enveloped-Data.  =
However, the S/MIME specification does not say how to use =
Authenticated-Enveloped-Data.  I think that is the work to be done.

Russ

