Re: [ftpext] New Version Notification for draft-bryan-ftp-hash-05
Anthony Bryan <anthonybryan@gmail.com> Tue, 13 July 2010 00:12 UTC
Return-Path: <anthonybryan@gmail.com>
X-Original-To: ftpext@core3.amsl.com
Delivered-To: ftpext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2EAD43A6869 for <ftpext@core3.amsl.com>; Mon, 12 Jul 2010 17:12:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.274
X-Spam-Level:
X-Spam-Status: No, score=-2.274 tagged_above=-999 required=5 tests=[AWL=0.325, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mQlh3olcNUsT for <ftpext@core3.amsl.com>; Mon, 12 Jul 2010 17:12:16 -0700 (PDT)
Received: from mail-iw0-f172.google.com (mail-iw0-f172.google.com [209.85.214.172]) by core3.amsl.com (Postfix) with ESMTP id DEB103A68B0 for <ftpext@ietf.org>; Mon, 12 Jul 2010 17:12:15 -0700 (PDT)
Received: by iwn38 with SMTP id 38so5452574iwn.31 for <ftpext@ietf.org>; Mon, 12 Jul 2010 17:12:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=PCXYDPEoexaVW7PEpbK1vRb+b1Iai1E4D0a+sJh+3Os=; b=KjPuUngGGsRa51FSdZT552g0DyHExIN63chb4qr5U4weBliluC726Ws2ppzU3TvwDK DS9V+aaTmGDzWntfYX6yhmnZUGB9Ld/yWpQZJEWUgYQSiTPbDD64WTY1DbNFlOSWrmNr 4G+1Il0KaLSuStpYJyBBKsALCP6WRxvK+4yEg=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; b=PspUPjlmp7aRCZRUou91yd3lXchbhGvRxCHfmopNLN52ZutebaSwL3r802A9mQaVOb W9v5npLaSqgqZsUh9sksFyEzwZMrxAVhW2RLSnboMZhaPPiUsesxHMwuX4E9lUhDYs30 AbUMe5j6cTCxBC8rOuygPPn2rB1FE8Qu037Gg=
MIME-Version: 1.0
Received: by 10.231.168.135 with SMTP id u7mr15036701iby.125.1278979943034; Mon, 12 Jul 2010 17:12:23 -0700 (PDT)
Received: by 10.231.161.143 with HTTP; Mon, 12 Jul 2010 17:12:22 -0700 (PDT)
In-Reply-To: <C1EBA743-A82B-4C6A-8D3D-2CDC44080480@muada.com>
References: <20100629052221.092623A6A5C@core3.amsl.com> <alpine.DEB.2.00.1006300000470.1493@tvnag.unkk.fr> <AANLkTikZFhGd3PIwDNrNcKymcoRzc4RHxIJU8TGPztTp@mail.gmail.com> <alpine.DEB.2.00.1006291639050.30072@familiar.castaglia.org> <D2D3FF30-3B2D-4EFA-A308-18A8A56DE596@muada.com> <AANLkTikPOdAaVSO7wsfEFsXtZwKoBOAWoI9qwnF_wF1F@mail.gmail.com> <C1EBA743-A82B-4C6A-8D3D-2CDC44080480@muada.com>
Date: Mon, 12 Jul 2010 20:12:22 -0400
Message-ID: <AANLkTinsMNS5k0aSa7-cNadnJ6-z5o2thHfv3rj5SpFw@mail.gmail.com>
From: Anthony Bryan <anthonybryan@gmail.com>
To: Iljitsch van Beijnum <iljitsch@muada.com>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
Cc: ftpext@ietf.org
Subject: Re: [ftpext] New Version Notification for draft-bryan-ftp-hash-05
X-BeenThere: ftpext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: <ftpext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ftpext>, <mailto:ftpext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ftpext>
List-Post: <mailto:ftpext@ietf.org>
List-Help: <mailto:ftpext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ftpext>, <mailto:ftpext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jul 2010 00:12:18 -0000
On Mon, Jul 12, 2010 at 7:01 PM, Iljitsch van Beijnum <iljitsch@muada.com> wrote: > On 13 jul 2010, at 0:39, Anthony Bryan wrote: > >> unless I'm misunderstanding, this would be MORE indirect, unoptimized, >> complex and DoSy than the current draft. > > I'll grant you more indirect and more complex. But don't forget the first rule of client-server: let the client do the hard work. from what I understand, your proposal involves potentially more work on the server? >> to be able to answer whether a hash is correct, the server still needs >> to know the correct hash? >> when you meet someone, do you ask "is your name Bob? no, how about >> Jim? no, Ed?" or do you just come right out and ask "what's your >> name?" which is simpler? > > Ah, but the question isn't "what's your name" but something that requires a rather expensive operation, which is always a nice DoS vector. I don't get it...either way, the server and client both have to perform the expensive operation, right? the server caches hashes or can limit the use of HASH, as Paul mentioned... I haven't heard of this as a problem for Instance Digests (8 years old), Content-MD5 (15 years), or the current 10 nonstandard FTP hash/checksum commands (9 years), even though I've brought it up before. >> you mention partial file hashes, some of those nonstandard commands >> like XCRC and XMD5 support it with a byte range. >> do you think HASH should support partial file hashing? > > No, because that way the client could ask the server to do an almost infinite number of hashes on a single file, and it makes it impossible for the server to precompute the hashes. right, there are reasons against partial file hashes/Content-MD5. does everyone think they are insurmountable? I'm personally against it as it involves more work! :) -- (( Anthony Bryan ... Metalink [ http://www.metalinker.org ] )) Easier, More Reliable, Self Healing Downloads
- Re: [ftpext] New Version Notification for draft-b… Daniel Stenberg
- Re: [ftpext] New Version Notification for draft-b… Anthony Bryan
- Re: [ftpext] New Version Notification for draft-b… TJ Saunders
- Re: [ftpext] New Version Notification for draft-b… Iljitsch van Beijnum
- Re: [ftpext] New Version Notification for draft-b… Paul Ford-Hutchinson
- Re: [ftpext] New Version Notification for draft-b… Anthony Bryan
- Re: [ftpext] New Version Notification for draft-b… Iljitsch van Beijnum
- Re: [ftpext] New Version Notification for draft-b… Anthony Bryan
- Re: [ftpext] New Version Notification for draft-b… Iljitsch van Beijnum
- Re: [ftpext] New Version Notification for draft-b… Richard Koenning
- Re: [ftpext] New Version Notification for draft-b… Tim Kosse