Re: [Last-Call] Last Call: <draft-gont-numeric-ids-sec-considerations-06.txt> (Security Considerations for Transient Numeric Identifiers Employed in Network Protocols) to Best Current Practice

Fernando Gont <fgont@si6networks.com> Fri, 01 January 2021 11:04 UTC

Return-Path: <fgont@si6networks.com>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F2E4D3A0927; Fri, 1 Jan 2021 03:04:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N5qArp3QFFQl; Fri, 1 Jan 2021 03:04:17 -0800 (PST)
Received: from fgont.go6lab.si (fgont.go6lab.si [91.239.96.14]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 88C4B3A09CF; Fri, 1 Jan 2021 03:04:15 -0800 (PST)
Received: from [192.168.1.13] (unknown [190.179.127.231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by fgont.go6lab.si (Postfix) with ESMTPSA id 4082828068F; Fri, 1 Jan 2021 11:04:09 +0000 (UTC)
To: Paul Wouters <paul@nohats.ca>
Cc: Eric Rescorla <ekr@rtfm.com>, last-call@ietf.org, Benjamin Kaduk <kaduk@mit.edu>, draft-gont-numeric-ids-sec-considerations@ietf.org
References: <160735373732.25981.15176977559155786235@ietfa.amsl.com> <CABcZeBM636h_XKwbpZb69TWLTq8-5n0=6CRAqhsB+pWzoZ2a7A@mail.gmail.com> <20201214034604.GT64351@kduck.mit.edu> <CABcZeBPgSFL=859oZGqm0V-WG+GQLmPqAX=pPjYbur5qTcgfVg@mail.gmail.com> <c4302926-76b3-3932-f5b6-7093a48ea8@nohats.ca> <c407fe1e-e359-1455-8c25-2ee621def723@si6networks.com> <782869c9-49c6-8558-f24c-f3c134c1a4c@nohats.ca>
From: Fernando Gont <fgont@si6networks.com>
Message-ID: <d064ad14-aa75-fe3b-3fa4-2c6fd346380c@si6networks.com>
Date: Fri, 01 Jan 2021 08:03:48 -0300
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.1
MIME-Version: 1.0
In-Reply-To: <782869c9-49c6-8558-f24c-f3c134c1a4c@nohats.ca>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/RocNJvNlCLVDL0s5kHvxWSY49BQ>
Subject: Re: [Last-Call] Last Call: <draft-gont-numeric-ids-sec-considerations-06.txt> (Security Considerations for Transient Numeric Identifiers Employed in Network Protocols) to Best Current Practice
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Jan 2021 11:04:26 -0000

On 31/12/20 14:42, Paul Wouters wrote:
[....]
>> 3) What the "controversy" is all about?
> 
> That I'm a little confused about too. I don't follow Theo de Raadt's
> reasoning of the end of the world.

I believe he has been quite explicit.

The OpenBSD crew had to figure out (and fix!) flawed numeric IDs for 
many different protocols, on their own, because the protocol 
specifications that we (IETF) shipped were flawed in that respect. Doing 
so not only has taken them a lot of time and effort, but has also been 
non-trivial. This eventually had to be done independently by developers 
of different operating systems, and in same cases, choices made to fix 
the flaws led to interoperability issues.

So it's not hard to follow Theo when, given a very long history of 
flawed numeric IDs in our specs, when there's finally some effort to 
improve that, there's push-back from some folks on the basis of:

* Objecting things that are not part of our document (!)

* Arguing that since there's a spec coming that fails to follow our
   advice, the right thing to do is to shoot down the advice, rather than
   fixing the spec that has problems.

In your email, you claimed "It is [..] a really low bar that we should 
be already meeting at the IETF in general at this point."
Clearly, that bar has not been met, and is not being met. So this 
document tries to be as explicit as possible recommending protocol specs 
authors to meet that bar, and how to do it, such that we stop repeating 
the same mistakes over and over again.

Thanks,
-- 
Fernando Gont
SI6 Networks
e-mail: fgont@si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492