Re: [hybi] Intermediaries and idle connections (was Re: Technical feedback.)

Justin Erenkrantz <justin@erenkrantz.com> Mon, 01 February 2010 04:18 UTC

Return-Path: <justin.erenkrantz@gmail.com>
X-Original-To: hybi@core3.amsl.com
Delivered-To: hybi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D53B23A6880 for <hybi@core3.amsl.com>; Sun, 31 Jan 2010 20:18:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.992
X-Spam-Level:
X-Spam-Status: No, score=-1.992 tagged_above=-999 required=5 tests=[AWL=-0.015, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xYOg3ngZbVTM for <hybi@core3.amsl.com>; Sun, 31 Jan 2010 20:18:48 -0800 (PST)
Received: from mail-px0-f186.google.com (mail-px0-f186.google.com [209.85.216.186]) by core3.amsl.com (Postfix) with ESMTP id 0C8F93A6859 for <hybi@ietf.org>; Sun, 31 Jan 2010 20:18:48 -0800 (PST)
Received: by pxi16 with SMTP id 16so4241576pxi.29 for <hybi@ietf.org>; Sun, 31 Jan 2010 20:19:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:received:in-reply-to :references:date:x-google-sender-auth:message-id:subject:from:to:cc :content-type; bh=UtZvwEipWHr/4TcUzqHblJNR50qp42i1VnmMDiG0Mno=; b=ZWS2I1I3SNOXYEG/S3zJS+gcv1W9Fd96pykbGvpU+wBVruiGG0V7SV0NkTbl4FeGX6 Y6taHwM3aZqIjPU+GhW/304g/h2A75JOPXb5dRw/RpVQk1RpJDEaFlkPPflzmh56ycc+ sKVyWFOzus9scJ+VV3RALrfQpUr4I0mHLK1Qk=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=CIatPoih9nBg49tj24oRS2kshQuvv8MH//CkqJ0q1YP/7IYrkjrkOVivPe19iiAFxQ dhv5bG3BnfHs15O6TNnt7yF6laYUFrDHhTBToUEWDwu+Dcvp4NfkrK3ecKj7HD02RXcO 70woKygezxIy/+xAYfb9MlNzrPNLNoScvzh2M=
MIME-Version: 1.0
Sender: justin.erenkrantz@gmail.com
Received: by 10.142.248.18 with SMTP id v18mr2744883wfh.97.1264997957863; Sun, 31 Jan 2010 20:19:17 -0800 (PST)
In-Reply-To: <2414195D-F1E0-43FE-8CED-401EAD9AA5F1@apple.com>
References: <4B62E516.2010003@webtide.com> <E379EA13-D58A-4BFB-A62D-2B931A54E276@apple.com> <4B63DD6B.5030803@webtide.com> <E765982E-06B5-48BC-B75D-02E3F9555018@apple.com> <4B64B179.9050502@webtide.com> <2D6C6FEE-2019-44E4-BD82-7BF68B30A518@apple.com> <4B64D0B3.7050503@webtide.com> <3A1BA23A-D9B6-48F5-8639-DE12CF9939C0@apple.com> <20100201010021.GA20940@shareable.org> <2414195D-F1E0-43FE-8CED-401EAD9AA5F1@apple.com>
Date: Sun, 31 Jan 2010 20:19:17 -0800
X-Google-Sender-Auth: cfd07bf4b90479c9
Message-ID: <5c902b9e1001312019y7b5d219ahb8121a1be59bdf58@mail.gmail.com>
From: Justin Erenkrantz <justin@erenkrantz.com>
To: Maciej Stachowiak <mjs@apple.com>
Content-Type: text/plain; charset="ISO-8859-1"
Cc: Hybi <hybi@ietf.org>
Subject: Re: [hybi] Intermediaries and idle connections (was Re: Technical feedback.)
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2010 04:18:49 -0000

On Sun, Jan 31, 2010 at 7:08 PM, Maciej Stachowiak <mjs@apple.com> wrote:

> But it also seems to reduce the security benefit.

I've noticed a few mentions so far of "security" as a key driver for
having an hardcoded initialization sequence, but I can't just envision
the tangible security benefits from mandating this.

So, what is the threat model that this mechanism is trying to prevent?
 How do these threats differ from other attacks against HTTP?  --
justin