Re: [media-types] Request for review of Media Type application/lzip

Antonio Diaz Diaz <antonio@gnu.org> Fri, 28 April 2023 15:41 UTC

Return-Path: <antonio@gnu.org>
X-Original-To: media-types@ietfa.amsl.com
Delivered-To: media-types@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA295C1BE874 for <media-types@ietfa.amsl.com>; Fri, 28 Apr 2023 08:41:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.4
X-Spam-Level:
X-Spam-Status: No, score=-4.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gnu.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cNDESILYItQK for <media-types@ietfa.amsl.com>; Fri, 28 Apr 2023 08:41:32 -0700 (PDT)
Received: from eggs.gnu.org (eggs.gnu.org [IPv6:2001:470:142:3::10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8D5B7C1BE871 for <media-types@ietf.org>; Fri, 28 Apr 2023 08:41:32 -0700 (PDT)
Received: from fencepost.gnu.org ([2001:470:142:3::e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <antonio@gnu.org>) id 1psQDx-0001tk-2n; Fri, 28 Apr 2023 11:41:29 -0400
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=In-Reply-To:References:Subject:To:MIME-Version:From: Date; bh=excP7HlT6lPEvJhROAVYwzDmg7EkYpHVgFtHbJ4ifzU=; b=RDn1nCLiPoRHWOkq/h1R 3UJiGaWX44fV313siDue1u2FiRnGt3VFQK0JQMlg2sMp+1puGkUs3bHehmjqWEYZLTM8DUJcKcqaN SVyM0EpiL7NczZ6qhC+GlPCp46ixXI0Wp1hkeepLkNVQBt4WKFGUof7SZeswjo8Lsde0OPtHpx+jl WNqQ+4XIuaxfEkA2M/k3LKM37HiKCY0xn5V0IHkHLR1dD68AMGshiGokfSwM047blHDD2xhgC64Or 059TSXJywQ1GZt+qSGd2C6tiyG8OFkCEDJXmN17QesnC7Ab6kTfUb58CXXDIDISWCG/rFajjfH7GY lNbreI/UP2Zn4g==;
Received: from 93.red-81-34-173.dynamicip.rima-tde.net ([81.34.173.93] helo=[192.168.1.2]) by fencepost.gnu.org with esmtpsa (TLS1.0:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from <antonio@gnu.org>) id 1psQDw-00024S-Eu; Fri, 28 Apr 2023 11:41:28 -0400
Message-ID: <644BE956.2090503@gnu.org>
Date: Fri, 28 Apr 2023 17:42:14 +0200
From: Antonio Diaz Diaz <antonio@gnu.org>
User-Agent: Mozilla/5.0 (X11; U; Linux i586; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
CC: media-types@ietf.org, Antonio Diaz Diaz <antonio@gnu.org>
References: <644B04DC.8060503@gnu.org> <87bkj88kyn.fsf@kaka.sjd.se>
In-Reply-To: <87bkj88kyn.fsf@kaka.sjd.se>
Content-Type: text/plain; charset="ISO-8859-15"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/media-types/1VIu8fKou0w3RnQcJnL6L8GxHDE>
Subject: Re: [media-types] Request for review of Media Type application/lzip
X-BeenThere: media-types@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "IANA mailing list for reviewing Media Type \(MIME Type, Content Type\) registration requests." <media-types.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/media-types>, <mailto:media-types-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/media-types/>
List-Post: <mailto:media-types@ietf.org>
List-Help: <mailto:media-types-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/media-types>, <mailto:media-types-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Apr 2023 15:41:36 -0000

Hi Simon. Thank you for your review.

Simon Josefsson wrote:
>> I'm posting the IANA part of the draft here for review. Could you
>> please let me know if this media type proposal is OK? Thanks.
>
> Looks good to me, +1 on publication and registration.

Good! Thanks.

>>     Applications that use this media type:
>>        Any application where data size is an issue
>
> At first reading I didn't quite get this, how about:
>
>     Any application that desire to reduce the size of data

Good idea! Thanks.

I wasn't sure what to write here and I just edited the text in the entries 
for gzip (RFC 6713) and zstd (RFC 8878). Both say "anywhere data size is an 
issue".

> I assume there are no other use-cases for lzip.

I think so, except that one can use the compression ratio to infer features 
of the data being compressed, or even discover secret data when they are 
compressed together with known data. But those uses seem like side effects 
of lzip's function of reducing the size of the data.

>> 5.  Security Considerations
>
> This was well written, thank you!

You are welcome!

> I think a draft like this should discuss the problem of using the
> compressed data size as a side-channel to learn contents of encrypted
> data, how about this:

Edward Vielmetti already suggested[1] something similar taken from the 
security considerations of brotli. I'll try to compose a text that includes 
the concerns of both suggestions and will add it to the draft. Thanks.

[1] https://mailarchive.ietf.org/arch/msg/art/_ImeSvemvH_iMNfF71o0Gt5Ik7A/


Best regards,
Antonio.