Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Brian Dickson
On Wed, Dec 2, 2020 at 1:49 PM Stephen Farrell wrote: > > Hiya, > > On 02/12/2020 21:38, Willem Toorop wrote: > > Op 02-12-2020 om 21:37 schreef Stephen Farrell: > > > > > > > >>> ad 2) we need a value that’s synchronized well enough and monotonic. > >>> I honestly don’t see any value in using 6

Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Willem Toorop
Op 02-12-2020 om 22:49 schreef Stephen Farrell: > > Hiya, > > On 02/12/2020 21:38, Willem Toorop wrote: >> Op 02-12-2020 om 21:37 schreef Stephen Farrell: >> >> >> ad 2) we need a value that’s synchronized well enough and monotonic. I honestly don’t see any value in using 64-bit valu

Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Stephen Farrell
Hiya, On 02/12/2020 21:38, Willem Toorop wrote: Op 02-12-2020 om 21:37 schreef Stephen Farrell: ad 2) we need a value that’s synchronized well enough and monotonic. I honestly don’t see any value in using 64-bit value here. Using unixtime has a value in itself, it’s a well-known and there’s

Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Willem Toorop
Op 02-12-2020 om 21:37 schreef Stephen Farrell: >> ad 2) we need a value that’s synchronized well enough and monotonic. >> I honestly don’t see any value in using 64-bit value here. Using >> unixtime has a value in itself, it’s a well-known and there’s a >> little room for any implementer to mak

Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Stephen Farrell
Hiya, On 02/12/2020 18:25, Ondřej Surý wrote: Stephen, ad 1) the performance is crucial for DNS over UDP and PRF such as SipHash is more efficient than HMACs. No, it wasn’t consulted with CFRG, and I can’t speak for Willem, but I am confident enough to make the decision. SipHash is widely used

Re: [DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Ondřej Surý
Stephen, ad 1) the performance is crucial for DNS over UDP and PRF such as SipHash is more efficient than HMACs. No, it wasn’t consulted with CFRG, and I can’t speak for Willem, but I am confident enough to make the decision. SipHash is widely used for hash tables virtually anywhere now. ad 2)

[DNSOP] Secdir last call review of draft-ietf-dnsop-server-cookies-04

2020-12-02 Thread Stephen Farrell via Datatracker
Reviewer: Stephen Farrell Review result: Has Issues I see two issues here worth checking: 1. I don't recall SipHash being used as a MAC in any IETF standard before. We normally use HMAC, even if truncated. Why make this change and was that checked with e.g. CFRG? (And the URL given in the referen