Re: [MLS] *re*joining a group with the same identity key
Jon Millican <jmillican@fb.com> Wed, 25 July 2018 11:05 UTC
Return-Path: <prvs=074406ad34=jmillican@fb.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 50BFD130E1E for <mls@ietfa.amsl.com>; Wed, 25 Jul 2018 04:05:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.72
X-Spam-Level:
X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_DKIMWL_WL_HIGH=-0.01, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=fb.com header.b=Mq1MoYHZ; dkim=pass (1024-bit key) header.d=fb.onmicrosoft.com header.b=V1b4BCtc
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JvWN64fJ8VG3 for <mls@ietfa.amsl.com>; Wed, 25 Jul 2018 04:05:13 -0700 (PDT)
Received: from mx0a-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14FBF130DDF for <mls@ietf.org>; Wed, 25 Jul 2018 04:05:12 -0700 (PDT)
Received: from pps.filterd (m0001255.ppops.net [127.0.0.1]) by mx0b-00082601.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w6PB1cvg000316; Wed, 25 Jul 2018 04:05:12 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fb.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=facebook; bh=HXX9NDSesL+CaUgOWVtVaKDrbViWw/SiGcsbbIz73d0=; b=Mq1MoYHZT/H1ny/MTfLTJaA7/LRtxHKPEN2syfQPUTX2uXgOAn0WyuKKUcP/UC9CUWPb 8VgeTLFtc1rRmiKuNyCsm1yjSOdD3lZh6vqU6RObnRPVOZYvXKZzqy3mp3lMDZECs/mb tCSxjcZovn2XqaPDcwWOINRqr82rm9cjtpw=
Received: from maileast.thefacebook.com ([199.201.65.23]) by mx0b-00082601.pphosted.com with ESMTP id 2keqpa017r-1 (version=TLSv1 cipher=ECDHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 25 Jul 2018 04:05:12 -0700
Received: from NAM05-CO1-obe.outbound.protection.outlook.com (192.168.183.28) by o365-in.thefacebook.com (192.168.177.29) with Microsoft SMTP Server (TLS) id 14.3.361.1; Wed, 25 Jul 2018 07:05:11 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fb.onmicrosoft.com; s=selector1-fb-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HXX9NDSesL+CaUgOWVtVaKDrbViWw/SiGcsbbIz73d0=; b=V1b4BCtcey2UphFx9oLbxks8ZOhe/TWzd9ceY6HrA89N9XFx1J+Kx9tUDDPP7d4YdpZVO2QlyvkZgw6nwLe3TRFPcSx7Pec+RIADOZa7GRvihEWJo9A1ez5tpKpnIqJjdxDo3tG5OHD9vYCsnfdD+Qpw7ltOG3KVOYuPVmYy/DA=
Received: from SN6PR15MB2205.namprd15.prod.outlook.com (52.135.64.145) by SN6PR15MB2334.namprd15.prod.outlook.com (52.135.65.26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.973.21; Wed, 25 Jul 2018 11:05:09 +0000
Received: from SN6PR15MB2205.namprd15.prod.outlook.com ([fe80::543d:ab65:689f:8f6b]) by SN6PR15MB2205.namprd15.prod.outlook.com ([fe80::543d:ab65:689f:8f6b%4]) with mapi id 15.20.0995.014; Wed, 25 Jul 2018 11:05:09 +0000
From: Jon Millican <jmillican@fb.com>
To: Katriel Cohn-Gordon <me@katriel.co.uk>, "mls@ietf.org" <mls@ietf.org>
Thread-Topic: [MLS] *re*joining a group with the same identity key
Thread-Index: AQHUJAbi8+8/pJnc+E+jbg98l9wWk6Sf12gA
Date: Wed, 25 Jul 2018 11:05:09 +0000
Message-ID: <2046EE4E-2F25-4E89-8844-0EDAAABA2A38@fb.com>
References: <1532516469.3570686.1452294728.424CDA78@webmail.messagingengine.com>
In-Reply-To: <1532516469.3570686.1452294728.424CDA78@webmail.messagingengine.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [2620:10d:c092:200::1:c79a]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; SN6PR15MB2334; 20:zX/ajcM83rIfSL+3AJ+S3hqR6rKzGWo4eNDM48Q8prZgCjov9uLP6voThluBZFQ+IL/xKe4gosLSYy9J/KfmunyBrGnWuxk6DI7JQbUBSgKu7GeMuNDjxIaweDpd7XyJvDvVhy3AmRwPpEdmgevTs6wSYJ8tlGW9DKb7he4pWSI=
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: b68d1efd-5845-4cb9-ffdb-08d5f21e7c70
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989117)(5600073)(711020)(4534165)(4627221)(201703031133081)(201702281549075)(8990107)(2017052603328)(7153060)(7193020); SRVR:SN6PR15MB2334;
x-ms-traffictypediagnostic: SN6PR15MB2334:
x-microsoft-antispam-prvs: <SN6PR15MB233407D509F95A9BDA27B70BDA540@SN6PR15MB2334.namprd15.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(28532068793085)(158342451672863)(21748063052155);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(3002001)(3231311)(11241501184)(944501410)(52105095)(93006095)(93001095)(10201501046)(149027)(150027)(6041310)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123564045)(20161123562045)(20161123558120)(6072148)(201708071742011)(7699016); SRVR:SN6PR15MB2334; BCL:0; PCL:0; RULEID:; SRVR:SN6PR15MB2334;
x-forefront-prvs: 0744CFB5E8
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(136003)(396003)(366004)(346002)(376002)(39860400002)(199004)(53754006)(189003)(2616005)(36756003)(186003)(6306002)(6486002)(102836004)(99286004)(76176011)(486006)(476003)(229853002)(7736002)(2501003)(6506007)(5250100002)(53546011)(478600001)(46003)(8676002)(81156014)(8936002)(6116002)(14454004)(316002)(110136005)(11346002)(83716003)(81166006)(446003)(25786009)(6246003)(53936002)(5660300001)(256004)(86362001)(97736004)(106356001)(6436002)(2900100001)(236005)(6512007)(2906002)(105586002)(54896002)(82746002)(33656002)(68736007)(14444005); DIR:OUT; SFP:1102; SCL:1; SRVR:SN6PR15MB2334; H:SN6PR15MB2205.namprd15.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: fb.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: 7AosQA5u7lr6b4aRaMJfPicuRY8uKG91mEajlN4ZFmUGmN6QQthd/4PHA4Ks3vQmqA7gVEH/iyHY+/B4AiYxwDiCquyRVC3S1xqptc4rb5cfZk6rtVhatDUGetHs3I5KDEbkZu++CLadyQwKDgq3XAZBX0WAcVIRrZHQDWICRCfgw40Rpg5CqhiTNnSs7q4rfSPBzE/pnFlcguHrLNZM5iIhrMn5+pOQMBkqIdrrIGFu4YXOE3y970JTXF3hed++kjmcMG2ntSH1kLb8JrH/JMemoOp/76pnfWdYfEUVpase2YekUcIq5nCPGpZpn/mED/aMXKyDkiMdmc+iyG4uxZtcWidMaCR6SfAS0sOwTSE=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_2046EE4E2F254E8988440EDAAABA2A38fbcom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: b68d1efd-5845-4cb9-ffdb-08d5f21e7c70
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jul 2018 11:05:09.3153 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 8ae927fe-1255-47a7-a2af-5f3a069daaa2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR15MB2334
X-OriginatorOrg: fb.com
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-07-25_03:, , signatures=0
X-Proofpoint-Spam-Reason: safe
X-FB-Internal: Safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/QoJjOocd-2SBrtQoW0dHnXpLaBk>
Subject: Re: [MLS] *re*joining a group with the same identity key
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Jul 2018 11:05:17 -0000
One potential option that comes to mind is for the server to help it reinsert itself in the correct place. This would essentially amount to a join, but serving its own copath instead of the group’s frontier. We could then reject somebody double-joining their own identity key; under the assumption that this could only happen with a malicious server anyway. I don’t have strong feelings about this vs your proposed solution though. The main benefit would probably be just in terms of keeping the tree cleaner and minimising remove operations that need to be done. Jon On 25/07/2018, 12:01, "MLS on behalf of Katriel Cohn-Gordon" <mls-bounces@ietf.org<mailto:mls-bounces@ietf.org> on behalf of me@katriel.co.uk<mailto:me@katriel.co.uk>> wrote: Hi all, Here'a s case we might want to think about: what should happen if a current member of a group asks to join, with the same long-term key that they're already joined with? The simple answer is to forbid such joins, but this might happen if a device forgets its group state but remembers its identity key. (Perhaps it writes the group state to a local database and the write got corrupted.) Alternatively I see a handful of different ways we could support these joins, if we wanted to. Perhaps the simplest is to allow the device to double-join but require it to immediately delete the old copy of itself. best, k
- [MLS] *re*joining a group with the same identity … Katriel Cohn-Gordon
- Re: [MLS] *re*joining a group with the same ident… Jon Millican
- Re: [MLS] *re*joining a group with the same ident… Dennis Jackson
- Re: [MLS] *re*joining a group with the same ident… Richard Barnes
- Re: [MLS] *re*joining a group with the same ident… Peter Saint-Andre
- Re: [MLS] *re*joining a group with the same ident… Ted Hardie
- Re: [MLS] *re*joining a group with the same ident… Katriel Cohn-Gordon
- Re: [MLS] *re*joining a group with the same ident… Richard Barnes
- Re: [MLS] *re*joining a group with the same ident… Dennis Jackson