linux-crypto.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers3@gmail.com>
To: Juan Manuel Torres Palma <j.m.torrespalma@gmail.com>
Cc: linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org,
	davem@davemloft.net, herbert@gondor.apana.org.au,
	Jason Cooper <jason@lakedaemon.net>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Eric Rost <eric.rost@mybabylon.net>
Subject: Re: [PATCH] crypto: testmgr: add test vectors for skein
Date: Wed, 20 Jun 2018 16:27:47 -0700	[thread overview]
Message-ID: <20180620232747.GA111712@gmail.com> (raw)
In-Reply-To: <20180620221247.GA25379@randy-betty>

[+Cc Jason Cooper <jason@lakedaemon.net>]
[+Cc Greg Kroah-Hartman <gregkh@linuxfoundation.org>]
[+Cc Eric Rost <eric.rost@mybabylon.net>]

On Thu, Jun 21, 2018 at 07:12:47AM +0900, Juan Manuel Torres Palma wrote:
> On Wed, Jun 20, 2018 at 11:10:51AM -0700, Eric Biggers wrote:
> > Also, can you describe the users of Skein in the kernel?  If there are no users,
> > there's no need to move it out of staging, or even have it in the kernel at all
> > anymore.  I say that as someone who has had to volunteer to fix critical bugs
> > found by fuzzing in crypto algorithms for which it's unclear why they are in the
> > kernel at all, as there are no apparent users.
> 
> To be honest I'm not aware of anyone actually using Skein.
> 
> So by this are you suggesting that we drop support? If not removed, I believe
> it's better to use test vectors as regression tests for further modifications.
> 

Yes, either we remove Skein, *or* we fix all the bugs and other issues such as
the lack of test vectors and continue to maintain the code in the future, e.g.
responding to bug reports from fuzzers and keeping it up to date with API
changes.  But if there are no current or planned users, then removing it is the
obvious choice.  Note that it's been in staging for over 4 years, and AFAICS the
original commits say nothing about any actual users or even why the code would
even be useful.  There's no need to waste time doing work that no one cares
about, and creating more bloat and kernel attack surface.  Skein is a good hash
algorithm, but it wasn't selected as SHA-3, so I'm not sure who would actually
want to use it in the kernel now in preference to SHA-2, SHA-3, etc.

I did recently investigate the Threefish block cipher (which is used internally
by Skein) as a possible alternative for Speck for fast encryption on processors
with AES instructions.  But it wasn't fast enough, among other disadvantages.

Eric

  reply	other threads:[~2018-06-20 23:27 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-06-20 10:57 [PATCH] crypto: testmgr: add test vectors for skein Juan Manuel Torres Palma
2018-06-20 17:56 ` Eric Biggers
2018-06-20 18:26   ` Stephan Mueller
2018-06-20 18:10 ` Eric Biggers
2018-06-20 22:12   ` Juan Manuel Torres Palma
2018-06-20 23:27     ` Eric Biggers [this message]
2018-07-01  9:16     ` Herbert Xu
2018-07-01  9:47       ` Greg Kroah-Hartman
2018-07-01 16:32         ` Jason Cooper
2018-07-01 18:48           ` [PATCH] staging/skein: Remove Skein and Threefish code Jason Cooper

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180620232747.GA111712@gmail.com \
    --to=ebiggers3@gmail.com \
    --cc=davem@davemloft.net \
    --cc=eric.rost@mybabylon.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=herbert@gondor.apana.org.au \
    --cc=j.m.torrespalma@gmail.com \
    --cc=jason@lakedaemon.net \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).