Re: Last Call: <draft-nottingham-safe-hint-05.txt> (The "safe" HTTP Preference) to Proposed Standard

Dave Crocker <dhc@dcrocker.net> Tue, 28 October 2014 03:29 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92A281A00FF for <ietf@ietfa.amsl.com>; Mon, 27 Oct 2014 20:29:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.6
X-Spam-Level:
X-Spam-Status: No, score=-3.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_64=0.6, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j7iqain_Tuvm for <ietf@ietfa.amsl.com>; Mon, 27 Oct 2014 20:29:27 -0700 (PDT)
Received: from sbh17.songbird.com (sbh17.songbird.com [72.52.113.17]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADF4B1A1B3A for <ietf@ietf.org>; Mon, 27 Oct 2014 20:29:27 -0700 (PDT)
Received: from [192.168.1.66] (76-218-8-156.lightspeed.sntcca.sbcglobal.net [76.218.8.156]) (authenticated bits=0) by sbh17.songbird.com (8.13.8/8.13.8) with ESMTP id s9S3TOYU022186 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Mon, 27 Oct 2014 20:29:27 -0700
Message-ID: <544F0D8A.3010001@dcrocker.net>
Date: Mon, 27 Oct 2014 20:29:14 -0700
From: Dave Crocker <dhc@dcrocker.net>
Organization: Brandenburg InternetWorking
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Matthew Kerwin <matthew@kerwin.net.au>
Subject: Re: Last Call: <draft-nottingham-safe-hint-05.txt> (The "safe" HTTP Preference) to Proposed Standard
References: <20141028004920.51745.qmail@ary.lan> <544EF0A4.7090609@gmail.com> <544EFBC2.5070402@dcrocker.net> <CACweHNBUsJxkey8HzR5wg7O3E1PEu0FwghMwxO2zQhF4+2yaOA@mail.gmail.com> <544EFDA5.9000408@dcrocker.net> <CACweHNDGkg6eNvOYqid1QEd8jPkzVDFEu=B3cS-Qf4D0GJqy-g@mail.gmail.com>
In-Reply-To: <CACweHNDGkg6eNvOYqid1QEd8jPkzVDFEu=B3cS-Qf4D0GJqy-g@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.0 (sbh17.songbird.com [72.52.113.66]); Mon, 27 Oct 2014 20:29:27 -0700 (PDT)
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/P_vfWgJJALIIZTztyzxt0A6rCyg
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: dcrocker@bbiw.net
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Oct 2014 03:29:29 -0000

On 10/27/2014 8:19 PM, Matthew Kerwin wrote:
>     > Actually, there's Preference-Applied. I don't recall seeing that
...
>     Forgive me, but:  THAT HAS NOTHING TO DO WITH THIS DRAFT.
...
> ​It's a normative reference. While I support the draft, I'm still
> willing to play​ devil's advocate here. 

Devil's advocacy can be useful, but it requires some care.

The draft's reference to 7240 is quite narrow, pertaining only to the
basic mechanism used to communicate the preference.  It does not have
any discussion about browser response.


> Brian has managed to point out
> that, today, there's no metadata or side-channel communication from
> server to browser that suggests that the content is in anyway "safe",
> but by standardising Prefer:safe, we introduce Preference-Applied:safe,
> which allows servers to "lie" in metadata as well as in data.

Note that the Security Considerations section already cites exposures
with the mechanism and possible misbehaviors by the server.


d/

-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net