Re: [dispatch] Announcing a MUC with RFC4575

Peter Saint-Andre <stpeter@stpeter.im> Thu, 30 May 2013 17:38 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: dispatch@ietfa.amsl.com
Delivered-To: dispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 95C6A21F9354 for <dispatch@ietfa.amsl.com>; Thu, 30 May 2013 10:38:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.49
X-Spam-Level:
X-Spam-Status: No, score=-102.49 tagged_above=-999 required=5 tests=[AWL=0.109, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y7-d1Qqq7rrK for <dispatch@ietfa.amsl.com>; Thu, 30 May 2013 10:37:58 -0700 (PDT)
Received: from stpeter.im (mailhost.stpeter.im [207.210.219.225]) by ietfa.amsl.com (Postfix) with ESMTP id 50A9A21F91CE for <dispatch@ietf.org>; Thu, 30 May 2013 10:37:58 -0700 (PDT)
Received: from sjc-vpn2-825.cisco.com (unknown [128.107.239.233]) (Authenticated sender: stpeter) by stpeter.im (Postfix) with ESMTPSA id C7C724113B; Thu, 30 May 2013 11:50:49 -0600 (MDT)
Message-ID: <51A78E73.20903@stpeter.im>
Date: Thu, 30 May 2013 11:37:55 -0600
From: Peter Saint-Andre <stpeter@stpeter.im>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:17.0) Gecko/20130509 Thunderbird/17.0.6
MIME-Version: 1.0
To: Emil Ivov <emcho@jitsi.org>
References: <51744F5B.8010506@jitsi.org> <5175A133.5040309@stpeter.im> <5175A9C6.9010707@alum.mit.edu> <8393F7ED-51FD-4CE1-B8A3-FD95EA185016@vidyo.com> <CAHBDyN7r8kuOyfUmzCeYa3dYM7ZqtdvfTvkF4QSkiDTSTfN02w@mail.gmail.com> <5176A9B9.3050105@jitsi.org> <CAHBDyN65C8oxdY3_hX46biFtENYF3dwhyqc_66mG6Wvo0RYQtw@mail.gmail.com> <5176CBA0.6000602@stpeter.im> <51773F1B.3020907@jitsi.org> <51A51FDE.7000006@stpeter.im> <51A77F54.3040309@jitsi.org>
In-Reply-To: <51A77F54.3040309@jitsi.org>
X-Enigmail-Version: 1.5.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: "dispatch@ietf.org" <dispatch@ietf.org>, Jonathan Lennox <jonathan@vidyo.com>
Subject: Re: [dispatch] Announcing a MUC with RFC4575
X-BeenThere: dispatch@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DISPATCH Working Group Mail List <dispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dispatch>, <mailto:dispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dispatch>
List-Post: <mailto:dispatch@ietf.org>
List-Help: <mailto:dispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dispatch>, <mailto:dispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 May 2013 17:38:02 -0000

Yes, that looks good!

On 5/30/13 10:33 AM, Emil Ivov wrote:
> Thanks Peter,
> 
> I've just updated the security considerations but wanted to make sure
> they reflect what you said before resubmitting, so here they are:
> 
> https://github.com/emcho/grouptextchat-purpose/blob/master/draft-ivov-grouptextchat-purpose-02.txt
> 
> 
> Could you please confirm that this works for you?
> 
> Cheers,
> Emil
> 
> On 29.05.13, 00:21, Peter Saint-Andre wrote:
> On 4/23/13 8:10 PM, Emil Ivov wrote:
>>>> There it is then:
>>>>
>>>> http://tools.ietf.org/html/draft-ivov-grouptextchat-purpose
> 
> An additional security consideration might be opening another attack
> vector for the conference (e.g., chatroom flooding). Furthermore, an
> attack on the auxiliary chatroom might be easier (or harder) than an
> attack on the main conference depending on the security policies in
> effect. Emil, regarding such mismatches you might borrow some text
> from draft-ivov-xmpp-cusax, but I think it would also be helpful to
> describe the nature of the chatroom attack vector (you might find it
> helpful to look at Section 13 of XEP-0045, especially 13.6.)
> 
> Peter
> 
>>
>