Re: [BEHAVE] FW: New Version Notification for draft-reddy-behave-turn-auth-00.txt

Simon Perreault <simon.perreault@viagenie.ca> Fri, 26 April 2013 13:16 UTC

Return-Path: <simon.perreault@viagenie.ca>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E84C21F9914 for <behave@ietfa.amsl.com>; Fri, 26 Apr 2013 06:16:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YOprpUoFSnEs for <behave@ietfa.amsl.com>; Fri, 26 Apr 2013 06:16:13 -0700 (PDT)
Received: from jazz.viagenie.ca (jazz.viagenie.ca [IPv6:2620:0:230:8000::2]) by ietfa.amsl.com (Postfix) with ESMTP id 2D8BA21F990B for <behave@ietf.org>; Fri, 26 Apr 2013 06:16:13 -0700 (PDT)
Received: from porto.nomis80.org (unknown [193.49.160.97]) by jazz.viagenie.ca (Postfix) with ESMTPSA id 56059403E0; Fri, 26 Apr 2013 09:16:12 -0400 (EDT)
Message-ID: <517A7E1B.7000108@viagenie.ca>
Date: Fri, 26 Apr 2013 15:16:11 +0200
From: Simon Perreault <simon.perreault@viagenie.ca>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130402 Thunderbird/17.0.5
MIME-Version: 1.0
To: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
References: <913383AAA69FF945B8F946018B75898A149778C5@xmb-rcd-x10.cisco.com> <5177968F.6050805@viagenie.ca> <913383AAA69FF945B8F946018B75898A14978FF1@xmb-rcd-x10.cisco.com> <517A36D2.6040504@viagenie.ca> <913383AAA69FF945B8F946018B75898A1497986F@xmb-rcd-x10.cisco.com>
In-Reply-To: <913383AAA69FF945B8F946018B75898A1497986F@xmb-rcd-x10.cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 8bit
Cc: "behave@ietf.org" <behave@ietf.org>
Subject: Re: [BEHAVE] FW: New Version Notification for draft-reddy-behave-turn-auth-00.txt
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Apr 2013 13:16:14 -0000

Le 2013-04-26 15:05, Tirumaleswar Reddy (tireddy) a écrit :
>>>> - In section "4. Problems with TURN Authentication", what's the
>>>> difference between problems 1 and 2 ?
>>>
>>> [TR] Problem 1 seem to be possible even if strong password is used.
>>> since password does not change frequently, the attacker could keep
>>> trying a number of candidate passwords. [/TR]
>>
>> Doesn't that characteristic also apply to problem 2 ?
>
> Yes it does, Do you want us to merge problem 1 and 2 ?

Well, I'm just trying to understand. If 1 and 2 are the same problem, 
then yes they should be merged. At this point I don't see any difference 
between the two.

>> - Problem 4 could also include the REALM attribute, which could be
>> snooped and harvested similarly.
>
> Do you have an attack or privacy problem in mind with REALM that we can add ?

Not really. I guess that leaking the domain of a call is acceptable.

>> I don't think we can rely on the PCP stuff also applying to STUN. The
>> environments are very different, both on servers and clients.
>
> Agreed, though there could be some scenarios where PCP capable Firewall and TURN server could be co-located.

Right. I am more focused on the WebRTC use case, where the TURN server 
is operated by the WebRTC application provider, and thus completely 
separate from any firewall the user might be behind.

Simon
-- 
DTN made easy, lean, and smart --> http://postellation.viagenie.ca
NAT64/DNS64 open-source        --> http://ecdysis.viagenie.ca
STUN/TURN server               --> http://numb.viagenie.ca