[AVT] draft-ietf-avt-rtp-clearmode-02.txt review

John Lazzaro <lazzaro@CS.Berkeley.EDU> Wed, 17 September 2003 19:13 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA24930 for <avt-archive@odin.ietf.org>; Wed, 17 Sep 2003 15:13:32 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19zhjh-0002HP-Qc for avt-archive@odin.ietf.org; Wed, 17 Sep 2003 15:13:10 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h8HJD9oF008719 for avt-archive@odin.ietf.org; Wed, 17 Sep 2003 15:13:09 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19zhjX-0002Fz-U7; Wed, 17 Sep 2003 15:12:59 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19zhjG-0002Fe-VI for avt@optimus.ietf.org; Wed, 17 Sep 2003 15:12:43 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA24813 for <avt@ietf.org>; Wed, 17 Sep 2003 15:12:34 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19zhjF-0002Gm-00 for avt@ietf.org; Wed, 17 Sep 2003 15:12:41 -0400
Received: from snap.cs.berkeley.edu ([128.32.34.209] ident=root) by ietf-mx with esmtp (Exim 4.12) id 19zhjF-0002Gi-00 for avt@ietf.org; Wed, 17 Sep 2003 15:12:41 -0400
Received: (from lazzaro@localhost) by snap.CS.Berkeley.EDU (8.11.6/8.9.3-ZUUL) id h8HJCbh02448 for avt@ietf.org; Wed, 17 Sep 2003 12:12:37 -0700
Date: Wed, 17 Sep 2003 12:12:37 -0700
From: John Lazzaro <lazzaro@CS.Berkeley.EDU>
Message-Id: <200309171912.h8HJCbh02448@snap.CS.Berkeley.EDU>
To: avt@ietf.org
Subject: [AVT] draft-ietf-avt-rtp-clearmode-02.txt review
Sender: avt-admin@ietf.org
Errors-To: avt-admin@ietf.org
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Id: Audio/Video Transport Working Group <avt.ietf.org>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>


Hi everyone,

	Quick review of draft-ietf-avt-rtp-clearmode-02.txt:

  [1] There's an ID-nits issue on line length, according to "wc -L" the
  longest line is 90 characters over the 72-char limit (according to
  http://www.ietf.org/ID-nits.html)

  [2] Abstract formatting problem, the final line needs to be placed
  in the appropriate place.

  [3] In Section 5 final paragraph, the a=fmtp is discussed, yet 
  Clearmode has no defined fmtp parameters ... seems like there
  was a typo here (maybe "rtpmap" was meant instead of "fmtp"?).

	Finally, one potential security issue, I'm not a telephony guy
but ... are there any sort of in-band signalling security issues here?
I.e. if the stream is unauthenticated, could someone craft a single
RTP packet with a plausible timestamp and sequence number, inject it
into a Clearmode stream, and get network switching gear to do
something "interesting" for an attacker or for someone looking for
free phone calls?

	If so, one wonders if the "MAY" in the security considerations
for authentication is appropriate ... but as I said, I'm not a
telephony guy, and I've probably heard too many Captain Crunch
<http://www.wikipedia.org/wiki/Captain_Crunch> stories :-).

-------------------------------------------------------------------------
John Lazzaro -- Research Specialist -- CS Division -- EECS -- UC Berkeley
lazzaro [at] cs [dot] berkeley [dot] edu     www.cs.berkeley.edu/~lazzaro
-------------------------------------------------------------------------

_______________________________________________
Audio/Video Transport Working Group
avt@ietf.org
https://www1.ietf.org/mailman/listinfo/avt