Re: [homenet] [babel] about Babel security (questions for Juliusz Chroboczek)

Denis Ovsienko <denis@ovsienko.info> Fri, 29 June 2018 16:29 UTC

Return-Path: <denis@ovsienko.info>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3BDBA130DC8; Fri, 29 Jun 2018 09:29:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ovsienko.info
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ya8PzVDa_1fc; Fri, 29 Jun 2018 09:29:21 -0700 (PDT)
Received: from sender-of-o51.zoho.com (sender-of-o51.zoho.com [135.84.80.216]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0EA70130DC1; Fri, 29 Jun 2018 09:29:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1530289758; s=zohomail; d=ovsienko.info; i=denis@ovsienko.info; h=Date:From:To:Message-ID:In-Reply-To:References:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding; l=1685; bh=KfsfUD1ctHPrzgyEDqe/44KQhNDBsHwLy9CPabHyCOM=; b=otcndfsB2a5KWkRJ1u/Ty6yxbHlSnQ80hw5Orlbf07V8EgyTrTDMjKw4NJw4BAUu AaXd17oAPOx+Q2PkJS9K/7iU+wxqAei7yHOayDpdo+kR0LnDMVLZnhUEW7yeWMQjpo2 zeliAVVy2lTueL7v3hGXQQW5Fw0RXn6SaxJ007Bg=
Received: from mail.zoho.com by mx.zohomail.com with SMTP id 1530289758260365.99422948025756; Fri, 29 Jun 2018 09:29:18 -0700 (PDT)
Date: Fri, 29 Jun 2018 17:29:18 +0100
From: Denis Ovsienko <denis@ovsienko.info>
To: "\"Babel at IETF\"" <babel@ietf.org>, "\"homenet\"" <homenet@ietf.org>
Message-ID: <1644c60a033.c75360b277726.6584770912151361357@ovsienko.info>
In-Reply-To: <87tvpl9aww.wl-jch@irif.fr>
References: <1644a8a0be0.b4caee6f16267.1270300104515944073@ovsienko.info> <87tvpl9aww.wl-jch@irif.fr>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
X-Priority: Medium
User-Agent: Zoho Mail
X-Mailer: Zoho Mail
Archived-At: <https://mailarchive.ietf.org/arch/msg/homenet/VX_7wJtwPPEp7KPuhnvtmdPndF0>
Subject: Re: [homenet] [babel] about Babel security (questions for Juliusz Chroboczek)
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF Homenet WG mailing list <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jun 2018 16:29:24 -0000

Thank you for a prompt response Juliusz.

Right now I will comment only on one specific point, more follow-ups later.

 ---- On Fri, 29 Jun 2018 10:53:03 +0100 Juliusz Chroboczek <jch@irif.fr> wrote ---- 
[...]
 > > The specification of "Stenberg-style security" for Babel was never 
 > > published. It is June 2018 and I have never seen it, although I asked 
 > > to. 
 >  
 > It was presented at IETF 101 in March 2018 (at which you were present). 

I confirm I attended IETF-101 in person and listened to Antonin's talk and slides about DTLS for Babel. I did not see a written specification. At the meeting I did bring up the need to see a written spec.

So in this case "presented" does not go as far as "published".

 > The draft lives here: 
 >  
 >   https://github.com/jech/babel-drafts/tree/master/draft-decimo-babel-dtls 

Thank you for making this update, I am glad a written specification of Babel DTLS now exists (i.e. has been published). I have been asking since early 2016.

 > I am not an author.  Please ask the authors, not me, about why it hasn't 
 > been published yet. 

As far as the commit history goes, the file was first added to the repository above on 25 June 2018 (four days ago), then it was updated three times on 27 June 2018 and two times on 29 June 2018 (today, last time about three hours ago). The file is a 325 lines long .xml file, which yields a .txt file, which is 8 pages long, 4 of which are boilerplates, the TOC, references and the likes. The other 4 pages are the actual specification. The document lists 3 authors.

I have studied the document and I find it difficult to discuss right now, to be honest.

-- 
    Denis Ovsienko