[ippm] Re: John Scudder's Discuss on draft-ietf-ippm-encrypted-pdmv2-09: (with DISCUSS and COMMENT)
"nalini.elkins@insidethestack.com" <nalini.elkins@insidethestack.com> Thu, 23 January 2025 13:03 UTC
Return-Path: <nalini.elkins@insidethestack.com>
X-Original-To: ippm@ietfa.amsl.com
Delivered-To: ippm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E2F7C1840D2 for <ippm@ietfa.amsl.com>; Thu, 23 Jan 2025 05:03:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.801
X-Spam-Level:
X-Spam-Status: No, score=-1.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dOVyyBX2_PmQ for <ippm@ietfa.amsl.com>; Thu, 23 Jan 2025 05:03:33 -0800 (PST)
Received: from sonic312-29.consmr.mail.ne1.yahoo.com (sonic312-29.consmr.mail.ne1.yahoo.com [66.163.191.210]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2D24C18DB8D for <ippm@ietf.org>; Thu, 23 Jan 2025 05:03:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1737637412; bh=743OB7kYNyb08m0WrOI0TvwPGaDBmKUR4K7ChV0e4Jw=; h=Date:From:To:Cc:In-Reply-To:References:Subject:From:Subject:Reply-To; b=ScP6p2sKO0IRnuQPVod3vRFV3n583ByceOUyV3+QWrYFqaYvJ9jMRqXuq10A8Bh+4ZABsmLlnY2B+8mSvvL0YaL3iyF8WoyFIkJkYvg10JDYA3YhQX/zJ8rFWLNl0p5NlnmD/EDTbw37Qc/wmDw8lyHSIxgBaT5vrYLMpXaR++G3ghAMDH4k9nw+1dpLztxraV1ywWFWYVVhOPqrpoyuAxsCu7RduT7we9kk8ECj0mhRV2FFgI0TVtIG7fPRAg4yfiq6acTO4PGWr4Q478MkLM041ZrJM7YAlFZmG4PpA+HvpwPieXAhaTonyIv//xUMXWA/LE+Uhe830tVLaI1sbg==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1737637412; bh=oJnHiPNWvU5l9N5xGHCB9k0Gns3/GpFCOEMVUX/blso=; h=X-Sonic-MF:Date:From:To:Subject:From:Subject; b=RY+Nx/RZlBKfz8Obc53np1HTWsUNFoT0YLFYLzXH0bRpgv7X1c7RJ6Bv0BUWVWyP8JCtLXO0ZqYVGfEkp0tC7dMcmq3qs6OWPhya25zKvllPxOmxVqr8Nn5Wmg0iSPMU+8wiEt5lnax71VoQiOdTXyKKGEsSUanJw4sfw0VxrTkB6sf2Zi142KUmRBvOyr+ohZgyeKJJHY7TkwPuJ9+xbNapb9gUso5XaZ3kn976YJ3d+AlyXOh4RDopTa/hdwPYbf/qNUHXQM5GGFP6IvV/lF2N+kzVhYMHC55HUZDrJVpU29n7D/A4rIT0JCKDHVbyXRUUAQBrgHLb9AKLytSlPQ==
X-YMail-OSG: QRrJGCoVM1nk0PmEitmy.hgPyuWnXhPp_EID6k4CS3qrPTUrlNOmkJZ5dLBopNY sok.ZUj.PUmuWS9P44045EBREonuFNpg3qIGWofHvonfg9H9ENpLFxeIXGuQbyf90xRABiVKKIuP J294DVzWhliElMTu0w_65AATs3s4YveojWfl87_OziTE6dfwF6t0GSBIbvdc_ORkPrfGPMi5wlgn DYgt7B1rDUYLBLDx6c63AwmuWsw0bJdN4IaDYCnKW__cbcSz1UyZwgrvMHJeKqbOEcNJDtH1TT5e 2Myzh9ImAol8Ox5_jc2VotVzkzCg3CHMD4J9ADPU79Vl5AkaN7Znfh9GYSILsGsQ0U9WE62ddQrp _GD6UrCf6x28mftErlRG26VG8Fhwq_9vTA5vOCBsy94oQXNlSzvyrXkay_XtozC1n3mH5HZ7KUOj jO0jEyOrEg__4N3w3rexJ104IVJddF.6eE8TB51bXkLj0Cs3rLywILbtBfATM6P.3AJetkYcORM1 6jr3XG_Zw.nUmPfOICX2UKvFpHZbtdWchCEMb4P4BF1mCe3gL7EdnWWmotayOVEEv3rslydDgfee B.XfkQwC2IdDpTUjeZIVl.K9EybfrgwhXv_7FgijLXgXbH4jJtu2Frok5yeCwTn8Y.5.xRNrzVxM GP9JQJp0PofIvKWbEV5skqS6B_Cve3DVMcSJ_758ff96QLZ4royijTNcbMPRVZ3cKeZ5w_5O4fv_ 5wZHTXG07CMR17fufzp1EAiKSNIyGTjc8.HDxcVt7ft07XrlbsiQw1xJzGmdAui73K5PQFEQAUZ0 3d540K3xjj4lbKFnkpeKk6lgCTi1uUuZp.8As5u.6UqSrJ2WSXcbUw4OeGHdnJ5j2n_KA4z968PV 8OqNf83gGtywJIpeiZzYrr5n5p_AQ2BC4uSfXeolEfpCyzmn_Ncnoq_ND7px3ynVgYfYcaJ2ruIo 96FJ5JoWmWoqNPf2hdNvMfstN_u6eUW8QWABm_vGOuaMgTLH6GSMxqi4MIjN9yxnHeh7pE3JpgGS HL98yatNpdbRd_oQLVRGW89RRSWmPtbtNwzuHw7hVFoYF5OBWgDEm8UUbGhcGkNoLvqfgC5Y4JZp hktzI0I1mgA9.BrzpBAVLn0XJn82tYKCIRIl8yapui6srJfnHF4Z0sClgZjy4A6IWokv83.9t7gu CnZjv.E3V390.uRTiJvXlSyKxM5Z5QX0H2XSDBI8w6csUdcG1OZgjj5zSZJnBb8AO80jQ.nbzIf_ HT9t24W9YRLegeMORex8AubSaj7r8gzamFBWZRR80V3pHv._.6dxfCpxBFP6egVZZfEweXfJpZ2L R.5ksAuICK_HeBkI5bCEiYbrgsG_twD87_D1wrZQvtPFs1.bWRGX9OA8ZdXC5PYt3C1Tkyj4BPPE zy7t_.fA8P21DPgtscKTsgrDQ8ZWult4KOlsvcSPdwJBvQ7CjK3mNMtTZbTTkmK7pEW0kv5ZWgNY .uR1rMMGgo38SDd5SvD51QghnnZtjnahdUZxL07iE5CEXRI5lSKqnAbg5iztxYcvUlBGNUlhqMVN Q.mpphZG65uZhtZbbSNl6tGEGOOBu4df1Xtxb_XVNvRqsR9M5m4x5jBtA_XGFXbpMFzWq9SPGcre CwOpAAhizQLMvizx.2r7fEp7y4kGZyD838AyIpt.6H1MwGigCuGoH9CpdWcdGKsT43OO.HwyxKE4 u4jAiT5IR25WT1MrSLnVoY856.evU7WUFoIvzXp8XBV5C8LKy.N78uriJ.7klJ2a1S8nXqMk00gQ AmFFwa4XLRIR1wT00P6wV9Lu8UHlwou2m3nuxpPTtl6JIPTHuAQshsMm6XN_Jpe.dqV4fnun7FGC mgPRmWEOjN0pZhQDEDwcdFS.PA2RzbxYPBCBpRSNBt2kxzyfn7Q13tOF7fbSHseMCVL4HRMOqzSb 12FXbl15txIrAe9XqJ_di1mtCodQ6Dyp5mrFXuj4RvlMjjhOGtykeMpp9Jo6S3SQRIQv.HDPxhyc w0ZnqaXwXNU6zdkyk1b.lnZWBmyYkGBpzKFdxdF9fcMgwMePdY0nA6KNGAd3vuwi729DuBgGefBP _Cj1XzD_j0JPN8IQIXnF4s_quyK7hJY4q61Cn2IOPYEHJFuIwnRVUfsk5pGFsiwtanKpKkTg0QFo pQBW_jBL9o1.VnCMgny3p.rTuEdmqWn909_nPNDvGwyAGwYbj1karDzUpCZk1KiR6u8hElsA1zIl G32U_7WaOklAf_zOF3Fycb.rRO_b3GUFGmEMebIARur2.W.t0MTBuHpuF8keVhdIkKLr5pw8jiY5 qFLtlI7XUmg--
X-Sonic-MF: <nalini.elkins@insidethestack.com>
X-Sonic-ID: bf9387a9-c17d-4dae-906b-aa15072d6a82
Received: from sonic.gate.mail.ne1.yahoo.com by sonic312.consmr.mail.ne1.yahoo.com with HTTP; Thu, 23 Jan 2025 13:03:32 +0000
Date: Thu, 23 Jan 2025 13:03:30 +0000
From: "nalini.elkins@insidethestack.com" <nalini.elkins@insidethestack.com>
To: John Scudder <jgs@juniper.net>
Message-ID: <1033143091.3461152.1737637410689@mail.yahoo.com>
In-Reply-To: <C78D84A9-BA5A-4475-8313-C9CA830E18C7@juniper.net>
References: <172952307207.1992747.8170300186220087852@dt-datatracker-78dc5ccf94-w8wgc> <298224448.6633034.1730013724935@mail.yahoo.com> <C272DEB0-875A-459A-A338-5CDE0B9EF074@juniper.net> <1421694947.9127371.1730519454145@mail.yahoo.com> <C78D84A9-BA5A-4475-8313-C9CA830E18C7@juniper.net>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_3461151_1370733250.1737637410686"
X-Mailer: WebService/1.1.23187 YMailNorrin
Message-ID-Hash: HHWQC6IGJUUH7QOEQI6CN46GU6MPOBB7
X-Message-ID-Hash: HHWQC6IGJUUH7QOEQI6CN46GU6MPOBB7
X-MailFrom: nalini.elkins@insidethestack.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ippm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, "draft-ietf-ippm-encrypted-pdmv2@ietf.org" <draft-ietf-ippm-encrypted-pdmv2@ietf.org>, "ippm-chairs@ietf.org" <ippm-chairs@ietf.org>, "ippm@ietf.org" <ippm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ippm] Re: John Scudder's Discuss on draft-ietf-ippm-encrypted-pdmv2-09: (with DISCUSS and COMMENT)
List-Id: IETF IP Performance Metrics Working Group <ippm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ippm/ZO7sd6E2IglwtoHuAH_U9DrDXgI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ippm>
List-Help: <mailto:ippm-request@ietf.org?subject=help>
List-Owner: <mailto:ippm-owner@ietf.org>
List-Post: <mailto:ippm@ietf.org>
List-Subscribe: <mailto:ippm-join@ietf.org>
List-Unsubscribe: <mailto:ippm-leave@ietf.org>
John, Sorry, it is my fault entirely. I have been completely swamped at my day job. But, I am now getting the team back together to revise the draft which I hope will address the questions that everyone has brought up. Thanks for checking in. Nalini Elkins CEO and Founder Inside Products, Inc. https://www.insidethestack.com PresidentIndustry Network Technology Councilhttps://www.industrynetcouncil.org On Wednesday, January 22, 2025 at 05:42:43 PM PST, John Scudder <jgs@juniper.net> wrote: Hi Nalini, I was reviewing my DISCUSS positions and wanted to check in to make sure you’re not waiting on me for anything. No rush, I just don’t want to be the long pole. —John On Nov 1, 2024, at 11:50 PM, nalini.elkins@insidethestack.com wrote: [External Email. Be cautious of content] John, > I’ve long since concluded that it’s usually impossible to know with certainty that one has considered every consequence of a > design decision concerning how it might be abused. The literature on side-channel attacks makes interesting reading (though > it would have been more appropriate yesterday, on Halloween… some of that stuff is pretty scary). True, indeed. There may be unintended consequences that I lack the imagination to foresee. > > Having said all this, we can certainly put some subset of the above as a guidance to the implementor in the draft to make it >> explicit that the value of the Global Counter can be seen by all users of the particular server. > That’s all I’m looking for… although now that I’m writing it, I wonder if it would also be worth saying the global pointer MAY be > omitted if so configured, for the benefit of a user who isn’t comfortable with the expanded attack surface. (I suppose this would > be achieved by just sending it as constant zero or something.)We will add some discussion of this topic as guidance to the implementor in the security / privacy considerations. I need to think a bit about what goes where. I think it is a good idea to allow MAY be omitted for the Global Pointer (should be calling this Global Packet Count!) but then it MUST be zeroes. Thanks, Nalini Elkins CEO and Founder Inside Products, Inc. https://www.insidethestack.com PresidentIndustry Network Technology Councilhttps://www.industrynetcouncil.org On Friday, November 1, 2024 at 06:31:58 PM GMT+1, John Scudder <jgs@juniper.net> wrote: Hi Nalini, Thanks for your careful reply. > On Oct 27, 2024, at 3:22 AM, nalini.elkins@insidethestack.com wrote: > > My thought on one client being able to see the aggregate number of packets sent by the server to all clients when using a server which serves multiple organizations is that, yes, this is an exposure but how one would use this in a way that is detrimental eludes me. Me, too, and thanks for your effort at thinking through some of the attack surface (which I’ve elided). I’ve long since concluded that it’s usually impossible to know with certainty that one has considered every consequence of a design decision concerning how it might be abused. The literature on side-channel attacks makes interesting reading (though it would have been more appropriate yesterday, on Halloween… some of that stuff is pretty scary). > Having said all this, we can certainly put some subset of the above as a guidance to the implementor in the draft to make it explicit that the value of the Global Counter can be seen by all users of the particular server. That’s all I’m looking for… although now that I’m writing it, I wonder if it would also be worth saying the global pointer MAY be omitted if so configured, for the benefit of a user who isn’t comfortable with the expanded attack surface. (I suppose this would be achieved by just sending it as constant zero or something.) Thanks, —John
- [ippm] John Scudder's Discuss on draft-ietf-ippm-… John Scudder via Datatracker
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… John Scudder
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… John Scudder
- [ippm] Re: John Scudder's Discuss on draft-ietf-i… nalini.elkins@insidethestack.com