Re: [babel] Secdir last call review of draft-ietf-babel-rtt-extension-04

Juliusz Chroboczek <jch@irif.fr> Thu, 12 October 2023 05:28 UTC

Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 70754C15107E; Wed, 11 Oct 2023 22:28:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=irif.fr
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3CYTrfgPpIEk; Wed, 11 Oct 2023 22:28:08 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A5EAC14CF18; Wed, 11 Oct 2023 22:28:02 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/82085) with ESMTP id 39C5RpEC007201; Thu, 12 Oct 2023 07:27:51 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id B0039A45F2; Thu, 12 Oct 2023 07:27:49 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=irif.fr; h= content-type:content-type:mime-version:user-agent:references :in-reply-to:subject:subject:from:from:message-id:date:date :received:received; s=dkim-irif; t=1697088467; x=1697952468; bh= gT14gboFaUUE7YNdrc6MvRcMbGPjcnVhTAILrhAwCVY=; b=ila0tG1djRq8Uw+p nfHa7n26Xh0SrjMxDtS+LlDIYuvpc4Mk4tKnDr+3mpbNVHrNEZmY734hy+soHuy/ Dqbz+m8gBXnBDsoHgBlxhUQWbjypR86+jDUyw3Rc9QTydGCxf1Z4PGglPtZcnlJQ H0sBULLlL/LTB5JI/ZrOTqe0WZ6+uVNJV6EY1r7MD44HApjj1zHTIZJkYQrakKe0 5Qr34JM7rv5G6o7e49PHcbkLxn41lAwqo3ABzrc+eqqjP2OptdOmiSoJMtoNyr// QlnzEvfAMxKyDWDmBI5+b990fNZqDNLGmvSIqHUnBv7IPAsUPJRo1IAuPPxZiMaR +DWgwQ==
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id yVayiGG5OL0J; Thu, 12 Oct 2023 07:27:47 +0200 (CEST)
Received: from pirx.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 5155BA45F1; Thu, 12 Oct 2023 07:27:46 +0200 (CEST)
Date: Thu, 12 Oct 2023 07:27:45 +0200
Message-ID: <874jiw1kby.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Shivan Kaul Sahib <shivankaulsahib@gmail.com>
Cc: David Schinazi <dschinazi.ietf@gmail.com>, secdir@ietf.org, babel@ietf.org, draft-ietf-babel-rtt-extension.all@ietf.org, last-call@ietf.org
In-Reply-To: <CAG3f7MhdTLs6LAbYMLDXdF9H5gE7fgv9xi66Su9cVT=q_p1jzg@mail.gmail.com>
References: <169690561656.636.8204474299201117349@ietfa.amsl.com> <87bkd6ztdk.wl-jch@irif.fr> <CAG3f7MjdVbd9F9n1tEfnxdiEg2TZG=rtDBojgaSZTQEcbsEPyw@mail.gmail.com> <CAPDSy+6cRezEKKEuLhZekY8rmG0=aDm_JtGkooWaaExaefOPRg@mail.gmail.com> <87cyxm42n0.wl-jch@irif.fr> <CAG3f7MhdTLs6LAbYMLDXdF9H5gE7fgv9xi66Su9cVT=q_p1jzg@mail.gmail.com>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/29.1 Mule/6.0
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset="US-ASCII"
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Thu, 12 Oct 2023 07:27:51 +0200 (CEST)
X-Miltered: at korolev with ID 652783D7.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 652783D7.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 652783D7.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/I62H-RCaMPchhJ13b4tZ4evdx28>
Subject: Re: [babel] Secdir last call review of draft-ietf-babel-rtt-extension-04
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Oct 2023 05:28:13 -0000

>> Uh-huh.  I could be wrong, but I think that Shivan is merely requesting
>> that we should mention the issue somewhere.  Which I agree with.

> I might be missing something, but the introduction of this document says that
> one of the motivating factors is that VPNs and tunnels can mess up routing and
> RTT calculation helps with that. Are we not talking about end-users' VPNs? 

The main application are tunnels and VPNs that are building blocks for
overlay networks.  The overlay networks are part of the provider's
infrastructure, and in some deployments the location of the routers is no
more secret than the location of any other infrastructure router.

(The main deployment is the backbone of Nexedi's distributed cloud.
Nexedi originally intended to deploy their cloud over the public IPv6
Internet, but found it too unreliable.  For the last 10 years, they have
been routing their in-cloud traffic using Babel over a fairly dense
overlay network, and they're very happy with the solution.)

However, there are other deployments, and some of those are intended to
escape internet censorship, so your concerns are certainly justified.

-- Juliusz