Re: HSTS Fingerprinting.

Jeff Hodges <jdhodges@google.com> Mon, 07 October 2019 23:49 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DDEA12006F for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 7 Oct 2019 16:49:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.251
X-Spam-Level:
X-Spam-Status: No, score=-10.251 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lu_kG0aXAhIq for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 7 Oct 2019 16:49:52 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [IPv6:2603:400a:ffff:804:801e:34:0:38]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F231120048 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Mon, 7 Oct 2019 16:49:52 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.89) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1iHcjD-0006LA-Px for ietf-http-wg-dist@listhub.w3.org; Mon, 07 Oct 2019 23:47:47 +0000
Resent-Date: Mon, 07 Oct 2019 23:47:47 +0000
Resent-Message-Id: <E1iHcjD-0006LA-Px@frink.w3.org>
Received: from mimas.w3.org ([2603:400a:ffff:804:801e:34:0:4f]) by frink.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <jdhodges@google.com>) id 1iHcjC-0006KX-L9 for ietf-http-wg@listhub.w3.org; Mon, 07 Oct 2019 23:47:46 +0000
Received: from mail-wr1-x435.google.com ([2a00:1450:4864:20::435]) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <jdhodges@google.com>) id 1iHcjB-00045e-00 for ietf-http-wg@w3.org; Mon, 07 Oct 2019 23:47:46 +0000
Received: by mail-wr1-x435.google.com with SMTP id w12so17233043wro.5 for <ietf-http-wg@w3.org>; Mon, 07 Oct 2019 16:47:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=SrvSciCdOyCzGKGZTOXxfdAwPqiGO7A03C+qUTOtH60=; b=h9eKUOEaHnrvBRdika+R2qcx6JGqtoiiC98JgPtoXKDZlqTbM/FgE2tJFgUZh+9Xlt kU1PK4okbUzxwXfgcTDothILy8nyVreSVSMtzzWF/oPGTudCZmpA3P+P5HgLp8ixhz9g wnVQuTWNTIw2gWUmlFHCXR6bL+lCrsjCmSnbmIXovpj4I0fraDJF01I3MG97aQ7D4kd7 Kd8uCLMoKbQKkHFmso/x7P2STdPKf/vZZ4aFuE3qSnYr3dJeZ0e+cGxvCSPE3I0ZzXig b4XVPMX0GkHY7haZMRG7cUkyQrehMQM6JEWI3//DDouogKKc7eunneo85dojHzK92Yz+ F5pg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=SrvSciCdOyCzGKGZTOXxfdAwPqiGO7A03C+qUTOtH60=; b=sAvUiYpsI1fGzl19UWS58rsrF5rbhDBAykRcBjmElQ33s/5EN6ADcU7nUwIf4mU1C/ JfO1bnzpSv71G/e7Mnr3LptXYv9x4+bj1lNJONjvLIeyNVmfxfoT7ckuzJ5R899q4OSi oehHAL3XzB6kt30P8W+/vzNoVM6znKoXUgMtq0XyI2t2PLiyLHZ7RglEKASV/dL4T1qQ dKDOQLYACB2GLF7W8MD4cOTzBaM3X9qcw2bcwK8KXtJNdLXyUsfpH62NQnrdnSwNQW4m wulWMUIvQA1C5/H5oVma7frt9uZ7DKX9uqArDTuZv9Wc76TVXu9SqYX0C9MbnOhL/05k oLMw==
X-Gm-Message-State: APjAAAVBQjULh+eSmGk9dmw+FrRcz4o5vRBPAZruoBAkpsVZnfOgfcrH 35/hWiKN5guU95ByPIC7A2GhGhuHSJG/gAkQryhK6g==
X-Google-Smtp-Source: APXvYqxnLWUWoHPoWQSlg8/daVNDZMbYax4uLBxttayEOczDCPhl1orLAkNQXpMKB8gqRcqHG3aAxrrU6vNyqWKIZQM=
X-Received: by 2002:adf:eb42:: with SMTP id u2mr4170764wrn.307.1570492042711; Mon, 07 Oct 2019 16:47:22 -0700 (PDT)
MIME-Version: 1.0
References: <CAKXHy=eh2JzMdKUFFKataSfomfQUcNc4kVhiRbjevQogEspvYA@mail.gmail.com> <CAKXHy=cTSHvkt1Tj6imt2=2begaO-RXcioj-8xiu=zi0-KjU0g@mail.gmail.com> <CD8BFB37-ADF5-4DA7-8C6B-6D93B550CAD8@mnot.net> <CAKXHy=fTO8aaFvEe5XNT6pg28L_af2ukoxgzsjAipUgd9tgBgw@mail.gmail.com>
In-Reply-To: <CAKXHy=fTO8aaFvEe5XNT6pg28L_af2ukoxgzsjAipUgd9tgBgw@mail.gmail.com>
From: Jeff Hodges <jdhodges@google.com>
Date: Mon, 07 Oct 2019 16:46:56 -0700
Message-ID: <CAOt3QXtxbHCeuqS73XBZFQFbmZz-Q6k-tHDxpS9WODj7mw_1yA@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Mark Nottingham <mnot@mnot.net>, HTTP Working Group <ietf-http-wg@w3.org>, John Wilander <wilander@apple.com>
Content-Type: multipart/alternative; boundary="0000000000005478c705945aacdb"
Received-SPF: pass client-ip=2a00:1450:4864:20::435; envelope-from=jdhodges@google.com; helo=mail-wr1-x435.google.com
X-W3C-Hub-Spam-Status: No, score=-20.8
X-W3C-Hub-Spam-Report: AWL=3.766, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1iHcjB-00045e-00 b5a22aeac7e5a5e36fcf86157a2d324c
X-Original-To: ietf-http-wg@w3.org
Subject: Re: HSTS Fingerprinting.
Archived-At: <https://www.w3.org/mid/CAOt3QXtxbHCeuqS73XBZFQFbmZz-Q6k-tHDxpS9WODj7mw_1yA@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/37043
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

[ just us ]

ah, ok, something to chat about on Wed -- ie, are you thinking a
monkey-patch of rfc6797 or an entire updated spec, or ...?



On Mon, Oct 7, 2019 at 4:48 AM Mike West <mkwst@google.com> wrote:

> Ok, thanks Mark. I'll aim to have an ID up by whenever the Singapore
> cutoff turns out to be.
>
> -mike
>
>
> On Thu, Oct 3, 2019 at 7:59 AM Mark Nottingham <mnot@mnot.net> wrote:
>
>> Hey Mike,
>>
>> I wouldn't treat the silence as indicative of disinterest.
>>
>> Would you be willing to write up a short draft explaining your proposal
>> and submit it for discussion in Singapore (presenting remotely if
>> necessary)? Even if you decide not to do it here, I suspect you'll be able
>> to reuse the markdown...
>>
>> Cheers,
>>
>>
>> > On 1 Oct 2019, at 11:47 pm, Mike West <mkwst@google.com> wrote:
>> >
>> > Ping!
>> >
>> > If this group doesn't feel any particular ownership, I'm happy to try
>> to define some web browsery behavior in W3C/WHATWG. If y'all would prefer
>> an RFC6797bis, great!
>> >
>> > -mike
>> >
>> >
>> > On Wed, Sep 18, 2019 at 3:10 AM Mike West <mkwst@google.com> wrote:
>> > A year or two ago, +John Wilander and others at Apple proposed some
>> changes to HSTS in
>> https://webkit.org/blog/8146/protecting-against-hsts-abuse/ that went
>> some way towards mitigating the abuses documented in Section 14.9 of
>> RFC6797. Given some shifts in the way we're thinking about some other
>> concepts, I've written up a short proposal at
>> https://github.com/mikewest/strict-navigation-security that builds upon
>> and simplifies Apple's proposal. We discussed it briefly at yesterday's
>> webappsec meeting, and there seems to be interest in doing something in
>> this space.
>> >
>> > +Mark Nottingham and +Jeff Hodges suggested that I loop this group into
>> that conversation, as the original websec group has disbanded. Is it a
>> topic this group would like to pick up? If not, would y'all be comfortable
>> with us defining some web browser behavior/Fetch integration in webappsec
>> that constrains the existing RFC?
>> >
>> > Thanks!
>> >
>> > -mike
>>
>> --
>> Mark Nottingham   https://www.mnot.net/
>>
>>

-- 
Thanks, HTH,

=JeffH