Re: [Captive-portals] Arguments against (any) Capport "API"

Martin Thomson <martin.thomson@gmail.com> Tue, 18 April 2017 00:50 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: captive-portals@ietfa.amsl.com
Delivered-To: captive-portals@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E09C12940F for <captive-portals@ietfa.amsl.com>; Mon, 17 Apr 2017 17:50:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X9GIi_PENnJN for <captive-portals@ietfa.amsl.com>; Mon, 17 Apr 2017 17:50:48 -0700 (PDT)
Received: from mail-lf0-x229.google.com (mail-lf0-x229.google.com [IPv6:2a00:1450:4010:c07::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A2211126C2F for <captive-portals@ietf.org>; Mon, 17 Apr 2017 17:50:47 -0700 (PDT)
Received: by mail-lf0-x229.google.com with SMTP id c80so22479102lfh.3 for <captive-portals@ietf.org>; Mon, 17 Apr 2017 17:50:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=8wcqZ/OwmAWqMClOUz6XJXOpWRNNorH2BFPUp5Vod+A=; b=VPcqygjcNspWG/GwyvJtmEw8dgNvKC+/d8PeopDb+vIhvAlI6DXF8LQVjfojnhuPua bOz5XocYIUG07UikN0OlVCCs58hBkS27I8PYH6Ob5r12kF4yBk77temxhlxqejN04SIT 4m0mmAKs84sEKC2AWiTYWY1bgQrEAEcD4kYuTEGUDLV+SrNynbwd7w93d6m6Casi1pWV NyuEj5dALs7d57nuYtXGXf0HbHCmidHo6Z6kiZ4yYwk2nwaKXVQexvXCD23gDfahnkW3 SZe421Myr0ys3mIoSwycL2d49JrepUMruy3eQIsSkYx8vRjyxEFq4VWHyYpt6xBKH3ZI yB/Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=8wcqZ/OwmAWqMClOUz6XJXOpWRNNorH2BFPUp5Vod+A=; b=ofdMXtbesQoF6+XLWbxTxO6WNNAQ0RsMxAUWEvKOqDDt5gCailg1oNqemWXsuE6abS zMOi+TMACOl/bGdvJlWaep4ZE3yv8mM4foPPraxNC1KAj9GrOMoOvXI7vVYGinUMMWDG Q6akr6zfzPIKyRYuJ9E3JVbe4suj1aCvvzRPXY/yc4rsKlzfhnpZ85dn9e3YGqPg6mBk NaAX6LsMsUln2003i3xfeDlDvK4BOftVwSqYb8NfVaMzJ3tk1Ww2+iU/MA02C5BjpPY2 4ST3MO9oRS7TtCgQrCWTY8z6D9HHyGinJBoL57UuT2GMYuXC9NWzfKqFQX5RYuv7XTQP sDWQ==
X-Gm-Message-State: AN3rC/4c+hCbW+FxRXp65JI8JfPkbDSGLeyo3hqu3uv+ep+CkZnrt0eB rer0YLGG+FArRCxAupqeQX4QBZoea1lw
X-Received: by 10.25.76.6 with SMTP id z6mr4126811lfa.172.1492476646030; Mon, 17 Apr 2017 17:50:46 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.46.83.5 with HTTP; Mon, 17 Apr 2017 17:50:44 -0700 (PDT)
In-Reply-To: <CADo9JyVBV7Pf29gs1Fxbrbdxf_rXPJQNKc7xEhrHuAxkYJcR=g@mail.gmail.com>
References: <CADo9JyU2wiEBB4L7ADSybt9se7jCN764JSEoHuGTcuiU_jDscQ@mail.gmail.com> <alpine.DEB.2.02.1704042139110.27978@uplift.swm.pp.se> <CADo9JyVr07w5GRpF+UzSBHRuo=V=3p9MeyhFdzB+5pZk7_amNw@mail.gmail.com> <D76BBBCF97F57144BB5FCF08007244A77059CE49@wtl-exchp-1.sandvine.com> <CADo9JyUnOfXSfXufzSk=QajyG2KXQfKzmQayca1kitRoAuwsqg@mail.gmail.com> <c12d4153-a053-8402-46a0-bfe6cb7228e9@sjrb.ca> <CADo9JyXPUPLU4aKueT7HxTU1CYfY=HrhqRz0OcCu4z1AivP-hg@mail.gmail.com> <E8355113905631478EFF04F5AA706E9870579488@wtl-exchp-1.sandvine.com> <18906.1491491628@dooku.sandelman.ca> <CADo9JyW3r7QzKsW78EuM9FOqW1waYGzjfuD7iTdWBXAR4eY8qQ@mail.gmail.com> <CABkgnnXA7PM65=20YNzziLR6Gv7ZpuSWvo0gHWt7aRdzAWr2bQ@mail.gmail.com> <5339533c-c73d-9be6-0e4f-2f9bdf47cac5@it.aoyama.ac.jp> <CADo9JyVBV7Pf29gs1Fxbrbdxf_rXPJQNKc7xEhrHuAxkYJcR=g@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Tue, 18 Apr 2017 10:50:44 +1000
Message-ID: <CABkgnnVOcEsYY3JAutQ67hM7QGgb6=7+GsKzn9XcGUe639mXsg@mail.gmail.com>
To: David Bird <dbird@google.com>
Cc: "Martin J. Dürst" <duerst@it.aoyama.ac.jp>, Michael Richardson <mcr+ietf@sandelman.ca>, "captive-portals@ietf.org" <captive-portals@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/captive-portals/ME5t6v9QGmzMdXZIdSIVQp5C2Wk>
Subject: Re: [Captive-portals] Arguments against (any) Capport "API"
X-BeenThere: captive-portals@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of issues related to captive portals <captive-portals.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/captive-portals/>
List-Post: <mailto:captive-portals@ietf.org>
List-Help: <mailto:captive-portals-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Apr 2017 00:50:49 -0000

On 7 April 2017 at 22:08, David Bird <dbird@google.com> wrote:
> To be clear, Gmail hyperlinked boingo.com for me... but, the point is that
> the UE/capport detection parsed and validated (checked the cert and cert
> status) of the FQDN. It is not some URL with questionable formatting...

I think that you missed my point.

The foundation for HTTPS is that there is an expectation of server
identity when navigation is initiated.  The same cannot be said in
this context.