Re: [hybi] IESG note?, was: Last Call: <draft-ietf-hybi-thewebsocketprotocol-10.txt> (The WebSocket protocol) to Proposed Standard
Willy Tarreau <w@1wt.eu> Tue, 06 September 2011 18:32 UTC
Return-Path: <w@1wt.eu>
X-Original-To: hybi@ietfa.amsl.com
Delivered-To: hybi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBFC721F8D1F for <hybi@ietfa.amsl.com>; Tue, 6 Sep 2011 11:32:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.052
X-Spam-Level:
X-Spam-Status: No, score=-4.052 tagged_above=-999 required=5 tests=[AWL=-2.009, BAYES_00=-2.599, HELO_IS_SMALL6=0.556]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LmIpUx+rtjZJ for <hybi@ietfa.amsl.com>; Tue, 6 Sep 2011 11:32:30 -0700 (PDT)
Received: from 1wt.eu (1wt.eu [62.212.114.60]) by ietfa.amsl.com (Postfix) with ESMTP id E1F2D21F8D1B for <hybi@ietf.org>; Tue, 6 Sep 2011 11:32:29 -0700 (PDT)
Received: (from willy@localhost) by mail.home.local (8.14.4/8.14.4/Submit) id p86IY3bt016194; Tue, 6 Sep 2011 20:34:03 +0200
Date: Tue, 06 Sep 2011 20:34:03 +0200
From: Willy Tarreau <w@1wt.eu>
To: "Richard L. Barnes" <rbarnes@bbn.com>
Message-ID: <20110906183403.GA16154@1wt.eu>
References: <20110711140229.17432.23519.idtracker@ietfa.amsl.com> <5355F3EF-DD59-4D3C-9578-84043A3B8E90@gbiv.com> <4E620772.9090900@gmx.de> <4E6228F9.2030108@gmx.de> <20110903194323.GA19164@1wt.eu> <C673E88C-D969-427E-B032-8695C7952253@bbn.com> <4e666234.ce640e0a.43f2.73ec@mx.google.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <4e666234.ce640e0a.43f2.73ec@mx.google.com>
User-Agent: Mutt/1.4.2.3i
Cc: hybi <hybi@ietf.org>
Subject: Re: [hybi] IESG note?, was: Last Call: <draft-ietf-hybi-thewebsocketprotocol-10.txt> (The WebSocket protocol) to Proposed Standard
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Sep 2011 18:32:30 -0000
On Tue, Sep 06, 2011 at 01:10:50PM -0500, Greg Longtin wrote: > Richard, > > > To put it in a more succinct, more alarmist way: How long will it be > > before WebSockets become popular for malware distribution? > > For traffic *from* client to server? Seems odd. > > As to traffic from server to client, that isn't masked, and hence, a > firewall could parse and scan it... I would also add that the part that is concerned is *not* within the HTTP messaging and that firewalls that would currently scan this would have to carefully consider the Upgrade header's value as well otherwise they could not emit any hypothesis about what they see there. For instance, the string "../../bin/sh -c" could be perfectly valid in an RDP session that runs over HTTP in Upgrade mode but might be dangerous in case of normal HTTP or even WebSocket. The difference is only known by the contents of the Upgrade header, otherwise it's random junk. So the masking here does not remove any ability for firewalls or other intermediaries to analyze a stream they were already able to analyze. And the masking was made cheap precisely so that those components will be adapted to scan the contents at a low cost. Regards, Willy
- [hybi] Last Call: <draft-ietf-hybi-thewebsocketpr… The IESG
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Thomson, Martin
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Julian Reschke
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Julian Reschke
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Julian Reschke
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Julian Reschke
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Francis Brosnan Blazquez
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Thomson, Martin
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Greg Wilkins
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Len Holgate
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Len Holgate
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Francis Brosnan Blazquez
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Len Holgate
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Francis Brosnan Blazquez
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Barry Leiba
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Len Holgate
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Francis Brosnan Blazquez
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mykyta Yevstifeyev
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Philippe Bernard
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Bruce Atherton
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Bruce Atherton
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Gabriel Montenegro
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… John Tamplin
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Greg Wilkins
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… David Endicott
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Roy T. Fielding
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Ted Hardie
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Keith Moore
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… John Tamplin
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Patrick McManus
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Alexey Melnikov
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Roy T. Fielding
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Roy T. Fielding
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Bjoern Hoehrmann
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Patrick McManus
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… John Tamplin
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Keith Moore
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Keith Moore
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Martin Rex
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Willy Tarreau
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Peter Saint-Andre
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Dave Cridland
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Mark Andrews
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Martin Rex
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Philip Homburg
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Roy T. Fielding
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Hector
- Re: [hybi] Last Call: <draft-ietf-hybi-thewebsock… Iñaki Baz Castillo
- [hybi] IESG note?, was: Last Call: <draft-ietf-hy… Julian Reschke
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Julian Reschke
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Roy T. Fielding
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Joel Martin
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Willy Tarreau
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Joel Martin
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Sylvain Hellegouarch
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Joel Martin
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Sylvain Hellegouarch
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Julian Reschke
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Peter Saint-Andre
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Richard L. Barnes
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Greg Longtin
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Willy Tarreau
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Roy T. Fielding
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Willy Tarreau
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Gabriel Montenegro
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Stephen Farrell
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Willy Tarreau
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Richard L. Barnes
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… John Tamplin
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… SM
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Stephen Farrell
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Peter Saint-Andre
- Re: [hybi] IESG note?, was: Last Call: <draft-iet… Willy Tarreau