Re: [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

Iñaki Baz Castillo <ibc@aliax.net> Tue, 06 September 2011 17:51 UTC

Return-Path: <ibc@aliax.net>
X-Original-To: hybi@ietfa.amsl.com
Delivered-To: hybi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFB5921F8C97; Tue, 6 Sep 2011 10:51:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.647
X-Spam-Level:
X-Spam-Status: No, score=-2.647 tagged_above=-999 required=5 tests=[AWL=0.030, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yn09FrgObk05; Tue, 6 Sep 2011 10:51:02 -0700 (PDT)
Received: from mail-qw0-f52.google.com (mail-qw0-f52.google.com [209.85.216.52]) by ietfa.amsl.com (Postfix) with ESMTP id 5CF0421F8C65; Tue, 6 Sep 2011 10:51:02 -0700 (PDT)
Received: by qwb8 with SMTP id 8so5654172qwb.25 for <multiple recipients>; Tue, 06 Sep 2011 10:52:49 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.229.47.129 with SMTP id n1mr4055276qcf.215.1315331569091; Tue, 06 Sep 2011 10:52:49 -0700 (PDT)
Received: by 10.229.79.207 with HTTP; Tue, 6 Sep 2011 10:52:48 -0700 (PDT)
In-Reply-To: <9FDB497E-960E-4F53-B978-C343564C39EE@bbn.com>
References: <942CCA6B-B784-441B-96CA-3506FFC439E1@bbn.com> <4E620046.2000400@isode.com> <E566DD99-64E5-47DF-A24C-3AA4E2EA20CA@bbn.com> <634914A010D0B943A035D226786325D422C0EB8DED@EXVMBX020-12.exch020.serverdata.net> <2E9037FF-84E3-4DAE-877C-592CB2DEA9A7@bbn.com> <CALiegfmn0e8Ei9x-KnH3Ejh3TBHy2gv-dfHMStoTYxZrjWH-Sg@mail.gmail.com> <9FDB497E-960E-4F53-B978-C343564C39EE@bbn.com>
Date: Tue, 06 Sep 2011 19:52:48 +0200
Message-ID: <CALiegfnxehr_4eFes+_hkTh+61PFLmHFed-RDBM6+5R2pKF_dw@mail.gmail.com>
From: Iñaki Baz Castillo <ibc@aliax.net>
To: "Richard L. Barnes" <rbarnes@bbn.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Cc: General Area Review Team <gen-art@ietf.org>, "hybi@ietf.org" <hybi@ietf.org>
Subject: Re: [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Sep 2011 17:51:03 -0000

2011/9/6 Richard L. Barnes <rbarnes@bbn.com>:
> Wouldn't you agree that HTTP servers would be less vulnerable to SlowLoris if they imposed limits on the number of HTTP headers of the length of time that a request must take?  All I'm suggesting is that this document suggest similar good habits.

I can agree on that, but just if it's within something like a
"Guidelines" section in the draft.

-- 
Iñaki Baz Castillo
<ibc@aliax.net>