From nobody Thu Jan 12 09:22:55 2023
Return-Path: <john.mattsson@ericsson.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 6358CC16FE4C
 for <core@ietfa.amsl.com>; Thu, 12 Jan 2023 09:22:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level: 
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001,
 RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
 URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001,
 URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id B3SRoClqNXw3 for <core@ietfa.amsl.com>;
 Thu, 12 Jan 2023 09:22:50 -0800 (PST)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com
 (mail-he1eur04on2048.outbound.protection.outlook.com [40.107.7.48])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 5E822C16FE4A
 for <core@ietf.org>; Thu, 12 Jan 2023 09:22:50 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
 b=iqOHrKaqQPifOm+0qfRvd/GvHE+h23XxoGRfgZn6j2UfVbRGOoyHx7ClyFqhlq8hQhLvIKkeH+6GgQnWMKkDp6kCNjpW988gQe8/palrSQ2CdlyY/jfO/4IsLfuhcGUTU5M/cj6aQjquRVq2MyTRyxO3M5lhrMtdtRssd19RKzADPSjGz7uWoUlb5tno+dgON+PmWtlripCeZdBd7qmGkbTnjDaeNZrUie/rBUND8tUil+0c/bkl7tolVJVC9tUz3E8NlS9YC/r1oRsLgNRloZNcLMXCTztikunjQIFMA//kLSDgaeHvejeN8j80o1VfErF3cc0u+KucI+oMJDdI8A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; 
 s=arcselector9901;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
 bh=k0xvmV1tlUbDTOj9tVl82LU9vQ28sub2qo6pvgz4/B4=;
 b=b7BSTtF88jiYvNmVrlq+siqm5SM/QA6iQiU/IhSYvdiyBczU7Ct8cZFmu2NNu61GklrcFC8J5qGv4UN9P5fJdiTUIAATDricc1hqZnvWcaJTxcYD2HzYxj30pj7augbjaMKkOjtxtVctwS8McORnEfSOqgVJlckTioVmiFaip2dr5IqDLeV7/GwkfCdgVBeaUdOOg/BGQgguV9MRElP99E/wRmlKFkAaAEeA0wRpshUzW0XYy7dgdfkYmjBfgZ0Fk94aXKzD34FjE8hZwXluzpbnMMNtlWRv/Oa6d2GUj8CzrVwmHNM0+hifdw5Dwzj6bDvJ8/3PS3UTVa3DjHk08g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
 smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com;
 dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com;
 s=selector1;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=k0xvmV1tlUbDTOj9tVl82LU9vQ28sub2qo6pvgz4/B4=;
 b=ViLXyOcJ+KovBPHZR/zNBcACIIiFjNbxic9gMgHCnJ5NUnT9vrZQI3Lpii3fj+arQEaVInLcby8WsunphZ0/ulR5VRlCoe+Ih92AQBY72O1WN0V9bKeWR4I6xRodVLf7lU71bkZOMff/EtmEaZMgXieIbfsgDqKZ50kfomrY8yw=
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com (2603:10a6:3:4b::8)
 by DB9PR07MB7226.eurprd07.prod.outlook.com (2603:10a6:10:21f::20) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5986.18; Thu, 12 Jan
 2023 17:22:44 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com
 ([fe80::fc77:42d2:1bc6:ec49]) by HE1PR0701MB3050.eurprd07.prod.outlook.com
 ([fe80::fc77:42d2:1bc6:ec49%12]) with mapi id 15.20.5986.019; Thu, 12 Jan
 2023 17:22:44 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "core@ietf.org" <core@ietf.org>
Thread-Topic: [core] WG Last Call on draft-ietf-core-conditional-attributes
Thread-Index: AQHZJql1xJtM47KJakCLptiA4dU7Fw==
Date: Thu, 12 Jan 2023 17:22:44 +0000
Message-ID: <HE1PR0701MB30504C1D963062A6219108AC89FD9@HE1PR0701MB3050.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: HE1PR0701MB3050:EE_|DB9PR07MB7226:EE_
x-ms-office365-filtering-correlation-id: 6caef3f3-a90c-423b-5c88-08daf4c19dff
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: DaBmT6GOEpbf/nE8zIyCJEBW7gvq35G8z10XjRpju9mTG9xtQmABFs3LebrkA0eD3Z2K37qnTDY2/gmy3ofTD/uQzgWtJA8DbGxXilPE1oFJvr05nUUTX7J95z3EpjY+qoEsMcSZPXWiEHuKH1t7vwQZI6+Q70lbdaWmKJGQgGAVz8fjNzIEKAhnTfgUsFKjdLd/y9J/3eJBAZlb8gROU7lbNlifgKudsFum9iQiuKKHHDi3zAv421by/FgxhYprWdxor8YnVcAsus9El/g6URgAQyetkGzunv5sVUfI4WgajNmrorRZpgqztYwsQADbeOh0SfiJwip6xmu/lc+yDzJjG82fYhmnFbd+5/XhLTvkzTEMorOCHhXX4Nki3JKiqVXWZPJLoun9DFzqSl9RWScxHpmd3fEbCQ1VLMJ865gUCIZvNQhdnQ6V9vGJKlHRix/TO9JfbVYtn/RH6DRTs7UG9GuPthDc5tayDh8iTfFi4kryuFWRJX9S7KpomhOgyXzUgLgCucXrbpw+F/AXEvQGS8ED70uSAIoF933hqUa9DhPk5qB/5egE0PhjOPBaxrMLpWL+++2v2DEKEV2KjwxQcSVyqMU9tqQTgJxYgMpI5FYwtI1sNKQ96pzoagCR6YxnPeLUt1wCN0zxImzMHXUtFCsyWlvDQUlTnzZPWdfD5K2igjgLj7EoWJDQNAllNCrAIWL9nena6SDmtsJG14UcJKfe1wj/PHw3Amad6gY=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; 
 IPV:NLI; SFV:NSPM;
 H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; 
 SFS:(13230022)(4636009)(346002)(39860400002)(396003)(376002)(366004)(136003)(451199015)(6506007)(38100700002)(122000001)(82960400001)(166002)(2906002)(966005)(478600001)(33656002)(4744005)(86362001)(26005)(186003)(44832011)(5660300002)(21615005)(316002)(7696005)(71200400001)(9686003)(83380400001)(8936002)(38070700005)(52536014)(55016003)(8676002)(41300700001)(91956017)(64756008)(6916009)(76116006)(66946007)(66446008)(66556008)(66476007);
 DIR:OUT; SFP:1101; 
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?us-ascii?Q?iHP4T+jkIl8rtLiZXViqFcOrx6/or8L3U2Llf1zHIx36V0la7mHcGO4hDYDz?=
 =?us-ascii?Q?2VuTuD8T0JoBLNvyvuJuFghHDJRibEBNyQwQ3fOpYQdv4XLPECjqztm46LL1?=
 =?us-ascii?Q?lQc2sknkxIe5zapBnFmylQ+n5ru7ko31gbDrRWs7Oxs60xPWeIb2GWmh6HCY?=
 =?us-ascii?Q?/MmkYGrbPNyIgAST2encFkTLcG8bJ68hTKh8EHdNNa415T4kpuEovRssY9A1?=
 =?us-ascii?Q?2+1jQVWTfuWGYm+uN4FWaasBbiw3PA+CSdVdvIKDc07dU2RFr2rqk/ZN6uy7?=
 =?us-ascii?Q?eJHjimvSmrjWHHEgt8dxQ+fJAUgtnXpVwzEPOh+tKFCZyxjPQtWjTyxb7h/e?=
 =?us-ascii?Q?b//UywAbzV4izQbwzxFzEehn0Br71MPAf4/AyNn+7LJWfWCl4dSGHI9OGgOt?=
 =?us-ascii?Q?CavRkpilCMMksL748FeZRIitJmL6TgadVdQkYM6+g0014LJh1ay48YPwXsTA?=
 =?us-ascii?Q?2YYnWm+l/479wXEYV/VZj0WFnrCCpRIFmPcHgKoiCSxE1436exgn8b3ix7TS?=
 =?us-ascii?Q?+HFz/9S3c5i4pnO71r6x4c+basBl/QnK0sq1RmFkTYh+4DT5gwQtKr+bkJKW?=
 =?us-ascii?Q?kuQpnkKvDtH9gqPMrQ8M5Iq2eBv0sQOwn2HTKeVnnLt3bqnCEPaeqHnVUE11?=
 =?us-ascii?Q?fB9ezsgQXMNxBrHLcz4z6OFhYpvs3tB/c9vw3acR47vG3NcdyYy2jzYijlGZ?=
 =?us-ascii?Q?EPHZp2IrxVGVQuPRoao9/7C61MQ2/RlacQzK/6bCdvuInL6w6gjo1s6qSeV/?=
 =?us-ascii?Q?1cyoKdF9uo0DQH1plLyjScszKVq1i3KkJbNNMMAf7f+6vLkJXiby8RJy98v3?=
 =?us-ascii?Q?xw9VnSh6YGuZ5xp8oTKe2c2MDQTxCiHf/1vJxmY5LnhtMbw5BJEyx1gm8OrL?=
 =?us-ascii?Q?eSWMvzit8FsSlm+8gzeRiZS1DmQZPRS7M3ultPX3vBolYSqugzgSoq/LG5aP?=
 =?us-ascii?Q?9/3I5tpQXQyvQGbczN4Uy+UfEsJW+QMvx4ZIOdc9Qn4plmxsrlVwxgdVx7Z9?=
 =?us-ascii?Q?zypxyaXNfnnNTE549xgEKxFxti+PPbcPpHVqRAk5auXqygA+llk4hYJinacF?=
 =?us-ascii?Q?ci8OTMNmkfNlPFWCH/NCP2QvbNZEt+kWB6qah1S+U1rdMUxLNDQGWCHWu6Zg?=
 =?us-ascii?Q?1VJOmtD6ZULSTswmbr/zKQdM+j6pdMRn+cX/5ZNwUiufjhpegvvnOPALED6O?=
 =?us-ascii?Q?dO0vKLbt9iTqZsr70k2dgFfNE6e1oQon/MpO/pyWaw7Y2Sae5cDdCFRe7/wV?=
 =?us-ascii?Q?kHWf3HQgsoCt/lW1CezQqi5gf2MdWZfMSU7NhL2T3X3ctfkzN+8Amgz69266?=
 =?us-ascii?Q?PyZdsC2fNQdekMAq6Bh6E6k0ckW43xVPmMT5HDmefzJJn3G7l4AQhdanhIMJ?=
 =?us-ascii?Q?6Cv9D2iSQyI1g0t/5B6TrWXFupEmKqIioCsDnQA+8RUaDZxzbS5P+eAsiPNK?=
 =?us-ascii?Q?hQaq7fTy2Jy/YLEvqhrbaFhxNvMABUZkEeRg35Oo3fpXPiwg1sle+vkpq2Rf?=
 =?us-ascii?Q?KLZP8GrLmP7Lwv52rCHLWoG9iZK2gVEamDTXtQYrwUw1TntqRrK90ceCEKxt?=
 =?us-ascii?Q?y/TQSK+FaK3dhd9AKS7zzg+erqmwPH9xWF5fAr1E3E70es0kmaguSSA3FoU2?=
 =?us-ascii?Q?7eLs1D364W1+YMJEXgBZpfw=3D?=
Content-Type: multipart/alternative;
 boundary="_000_HE1PR0701MB30504C1D963062A6219108AC89FD9HE1PR0701MB3050_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 6caef3f3-a90c-423b-5c88-08daf4c19dff
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Jan 2023 17:22:44.2657 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: z5uiL4PTeI6sl9bk6o52KGxjnpxpcR14If6ni4oA7R2AQmNWC4dg27CFmtslUS7PNdgOEui4Z2GQksSe/+UfxJsao6DEJArW8FXzP4dB1j8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR07MB7226
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/MPp2CS_W696GomNwpAsxww_SqaA>
Subject: Re: [core] WG Last Call on draft-ietf-core-conditional-attributes
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list"
 <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>,
 <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>,
 <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Jan 2023 17:22:54 -0000

--_000_HE1PR0701MB30504C1D963062A6219108AC89FD9HE1PR0701MB3050_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi,

The pmax attribute risks making amplification attacks far worse but as far =
as I can see the draft does not say a single word about this. See

https://www.ietf.org/staging/draft-irtf-t2trg-amplification-attacks-00.html

Before publishing I think the draft needs to describe this and normatively =
require sufficient mitigations from the implementation.

Cheers,
John


--_000_HE1PR0701MB30504C1D963062A6219108AC89FD9HE1PR0701MB3050_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:"Courier New";
	mso-fareast-language:EN-GB;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"en-SE" link=3D"#0563C1" vlink=3D"#954F72" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"SV">Hi,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"SV"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">The pmax attribute risks making=
 amplification attacks far worse but as far as I can see the draft does not=
 say a single word about this. See<o:p></o:p></span></p>
<pre><span lang=3D"EN-US"><br></span><a href=3D"https://www.ietf.org/stagin=
g/draft-irtf-t2trg-amplification-attacks-00.html">https://www.ietf.org/stag=
ing/draft-irtf-t2trg-amplification-attacks-00.html</a><o:p></o:p></pre>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Before publishing I think the d=
raft needs to describe this and normatively require sufficient mitigations =
from the implementation.<br>
<br>
Cheers,<br>
John</span><span lang=3D"EN-US"> </span><o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_HE1PR0701MB30504C1D963062A6219108AC89FD9HE1PR0701MB3050_--

