[core] Block aspects addressed in draft-ietf-core-attacks-on-coap-03.txt

Christian Amsüss <christian@amsuess.com> Tue, 13 June 2023 22:23 UTC

Return-Path: <christian@amsuess.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost []) by ietfa.amsl.com (Postfix) with ESMTP id C8EB7C15154F for <core@ietfa.amsl.com>; Tue, 13 Jun 2023 15:23:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id QuJEOoxQ1nCR for <core@ietfa.amsl.com>; Tue, 13 Jun 2023 15:23:19 -0700 (PDT)
Received: from smtp.akis.at (smtp.akis.at [IPv6:2a02:b18:500:a515::f455]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BFAE3C15153C for <core@ietf.org>; Tue, 13 Jun 2023 15:23:18 -0700 (PDT)
Received: from poseidon-mailhub.amsuess.com (095129206250.cust.akis.net []) by smtp.akis.at (8.17.1/8.17.1) with ESMTPS id 35DMNGVM032603 (version=TLSv1.2 cipher=ECDHE-ECDSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 14 Jun 2023 00:23:16 +0200 (CEST) (envelope-from christian@amsuess.com)
X-Authentication-Warning: smtp.akis.at: Host 095129206250.cust.akis.net [] claimed to be poseidon-mailhub.amsuess.com
Received: from poseidon-mailbox.amsuess.com (hermes.lan []) by poseidon-mailhub.amsuess.com (Postfix) with ESMTP id E74A222DDD; Wed, 14 Jun 2023 00:23:15 +0200 (CEST)
Received: from hephaistos.amsuess.com (hephaistos.lan [IPv6:2a02:b18:c13b:8010::32b]) by poseidon-mailbox.amsuess.com (Postfix) with ESMTPSA id 8504C24368; Wed, 14 Jun 2023 00:22:33 +0200 (CEST)
Received: (nullmailer pid 32187 invoked by uid 1000); Tue, 13 Jun 2023 22:22:32 -0000
Date: Wed, 14 Jun 2023 00:22:32 +0200
From: Christian Amsüss <christian@amsuess.com>
To: supjps-ietf@jpshallow.com
Cc: core@ietf.org
Message-ID: <ZIjsKLxLNCIOu70Y@hephaistos.amsuess.com>
References: <168650947092.62266.18419070105597824117@ietfa.amsl.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="+Y7PwvCzpymloJ2i"
Content-Disposition: inline
In-Reply-To: <168650947092.62266.18419070105597824117@ietfa.amsl.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/BJO0z9HwmIkpIQxGk6ZFF8UoueA>
Subject: [core] Block aspects addressed in draft-ietf-core-attacks-on-coap-03.txt
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jun 2023 22:23:22 -0000

Hello Jon,

you've had comments on earlier versions of attacks-on-coap that did not
result in a text change, and I'd like to check with you whether you
agree with the resolution:

In [1], you outlined an attack where exchanges of the shape
single-block1-many-block2 that have different request payloads would get
mixed up. In my understanding, this is not a working attack, as the
requests pulling the later block2 responses would contain the original
request -- and for identical requests, this is no different from the
case of payload-less requests of different times getting mixed up (which
is what ETag is for).

If you still think there is some of [77] that needs to be considered,
please follow up here -- otherwise, I'd mentally mark this one as

Best regards, and thanks for bringing up the item

[1]: https://mailarchive.ietf.org/arch/msg/core/tuI9NNtx5t3NDsK0zfhdvNGCmEg/
[77]: https://github.com/core-wg/echo-request-tag/issues/77

I shouldn't have written all those tank programs.
  -- Kevin Flynn