Re: [Captive-portals] Arguments against (any) Capport "API"

Dave Dolson <ddolson@sandvine.com> Tue, 18 April 2017 01:40 UTC

Return-Path: <ddolson@sandvine.com>
X-Original-To: captive-portals@ietfa.amsl.com
Delivered-To: captive-portals@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB6C61293F5 for <captive-portals@ietfa.amsl.com>; Mon, 17 Apr 2017 18:40:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JbLLXCklfFub for <captive-portals@ietfa.amsl.com>; Mon, 17 Apr 2017 18:40:22 -0700 (PDT)
Received: from mail1.sandvine.com (Mail1.sandvine.com [64.7.137.134]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EBBC51200C5 for <captive-portals@ietf.org>; Mon, 17 Apr 2017 18:40:21 -0700 (PDT)
Received: from WTL-EXCHP-1.sandvine.com ([fe80::ac6b:cc1e:f2ff:93aa]) by wtl-exchp-2.sandvine.com ([::1]) with mapi id 14.03.0319.002; Mon, 17 Apr 2017 21:40:20 -0400
From: Dave Dolson <ddolson@sandvine.com>
To: Martin Thomson <martin.thomson@gmail.com>, David Bird <dbird@google.com>
CC: Michael Richardson <mcr+ietf@sandelman.ca>, "Martin J. Dürst" <duerst@it.aoyama.ac.jp>, "captive-portals@ietf.org" <captive-portals@ietf.org>
Thread-Topic: [Captive-portals] Arguments against (any) Capport "API"
Thread-Index: AQHSrXaI8eoMbQ0LvUmcTBaIn9Y6W6G137YAgAACQoCAAAJ6gIAAAUgAgAACSYCAABa8gIAA+0HggAG+6QCAAJ9nAIAAMwGAgABjfQCAACiLAIAQjGYA///KzD8=
Date: Tue, 18 Apr 2017 01:40:18 +0000
Message-ID: <20170418014018.5161041.1589.8080@sandvine.com>
References: <CADo9JyU2wiEBB4L7ADSybt9se7jCN764JSEoHuGTcuiU_jDscQ@mail.gmail.com> <alpine.DEB.2.02.1704042139110.27978@uplift.swm.pp.se> <CADo9JyVr07w5GRpF+UzSBHRuo=V=3p9MeyhFdzB+5pZk7_amNw@mail.gmail.com> <D76BBBCF97F57144BB5FCF08007244A77059CE49@wtl-exchp-1.sandvine.com> <CADo9JyUnOfXSfXufzSk=QajyG2KXQfKzmQayca1kitRoAuwsqg@mail.gmail.com> <c12d4153-a053-8402-46a0-bfe6cb7228e9@sjrb.ca> <CADo9JyXPUPLU4aKueT7HxTU1CYfY=HrhqRz0OcCu4z1AivP-hg@mail.gmail.com> <E8355113905631478EFF04F5AA706E9870579488@wtl-exchp-1.sandvine.com> <18906.1491491628@dooku.sandelman.ca> <CADo9JyW3r7QzKsW78EuM9FOqW1waYGzjfuD7iTdWBXAR4eY8qQ@mail.gmail.com> <CABkgnnXA7PM65=20YNzziLR6Gv7ZpuSWvo0gHWt7aRdzAWr2bQ@mail.gmail.com> <5339533c-c73d-9be6-0e4f-2f9bdf47cac5@it.aoyama.ac.jp> <CADo9JyVBV7Pf29gs1Fxbrbdxf_rXPJQNKc7xEhrHuAxkYJcR=g@mail.gmail.com>, <CABkgnnVOcEsYY3JAutQ67hM7QGgb6=7+GsKzn9XcGUe639mXsg@mail.gmail.com>
In-Reply-To: <CABkgnnVOcEsYY3JAutQ67hM7QGgb6=7+GsKzn9XcGUe639mXsg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-c2processedorg: b2f06e69-072f-40ee-90c5-80a34e700794
Content-Type: text/plain; charset="windows-1256"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/captive-portals/WWrRbTKhOJDG59yC708na54Gk14>
Subject: Re: [Captive-portals] Arguments against (any) Capport "API"
X-BeenThere: captive-portals@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of issues related to captive portals <captive-portals.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/captive-portals/>
List-Post: <mailto:captive-portals@ietf.org>
List-Help: <mailto:captive-portals-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Apr 2017 01:40:24 -0000

In this context, one advantage is that the user device knows this is a special URL. It knows exactly why it is being presented. We may recommend the user be made clearly aware.

I think it is clearer than some random http or DNS that might be redirected (methods currently available)

David Dolson
‎
  Original Message
From: Martin Thomson
Sent: Monday, April 17, 2017 8:50 PM
To: David Bird
Cc: Michael Richardson; Martin J. Dürst; captive-portals@ietf.org
Subject: Re: [Captive-portals] Arguments against (any) Capport "API"


On 7 April 2017 at 22:08, David Bird <dbird@google.com> wrote:
> To be clear, Gmail hyperlinked boingo.com for me... but, the point is that
> the UE/capport detection parsed and validated (checked the cert and cert
> status) of the FQDN. It is not some URL with questionable formatting...

I think that you missed my point.

The foundation for HTTPS is that there is an expectation of server
identity when navigation is initiated.  The same cannot be said in
this context.

_______________________________________________
Captive-portals mailing list
Captive-portals@ietf.org
https://www.ietf.org/mailman/listinfo/captive-portals