logoalt Hacker News

loeg • today at 12:00 AM • 2 replies • view on HN

> being familiar with cryptographic protocols and formats where the hash algorithm is usually a parameter that can vary for each concrete hash.

This flexibility ("agility") in cryptographic protocols is often seen as a mistake today, actually.


Replies

WorldMaker • today at 1:57 AM

Cryptographic protocols have been moving towards something of a compromise in flexibility. "Everything flexible" is a security risk, especially when "everything" includes "fallback to nothing secure". "No flexibility" is a security risk because you can't upgrade. The middle path is something like "version numbers" with hard breakpoints. "I only support v2 of this cryptographic protocol and will not fallback to v1."

Which is sort of the hash algorithm approach git is taking with incompatible versions and a version break.

layer8 • today at 7:04 AM

No, the mistake is to not restrict the allowed algorithm suites in a given deployment and in default configurations. However, for the allowed algorithms to be able to change over time, algorithm agility is needed. For example, the migration from RSA to ECDSA (and variants) to PQC algorithms, and from smaller to larger key sizes, would be vastly more difficult without algorithm agility.

All modern formats, such as JOSE and COSE, continue to be built on algorithm agility, and that’s unlikely to change.

Older protocol elements that had SHA-1 or SHA-256 hardcoded have invariably been replaced or supplemented with elements using an algorithm parameter.