Re: [MLS] [new-work] WG Review: Messaging Layer Security (mls)

Peter Saint-Andre <stpeter@mozilla.com> Fri, 25 May 2018 16:22 UTC

Return-Path: <stpeter@mozilla.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6AF8A127023 for <mls@ietfa.amsl.com>; Fri, 25 May 2018 09:22:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mozilla.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yxWL8QoeP9zi for <mls@ietfa.amsl.com>; Fri, 25 May 2018 09:22:49 -0700 (PDT)
Received: from mail-io0-x244.google.com (mail-io0-x244.google.com [IPv6:2607:f8b0:4001:c06::244]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 37BBD12704A for <mls@ietf.org>; Fri, 25 May 2018 09:22:49 -0700 (PDT)
Received: by mail-io0-x244.google.com with SMTP id p124-v6so7024935iod.1 for <mls@ietf.org>; Fri, 25 May 2018 09:22:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mozilla.com; s=google; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to; bh=A+an3CsCLxWd26AnSrEJ7MqPNCXkCxIApNG5jViBjS0=; b=RcZ7umdvcYqao6tuPF0C8jTPbGOCpOxJl2NvyxZKDg/X2ZjBlBrVyEYFLQUpdtkyQt wpIpdnAo6kjZXVI8zgSDY4N3S86T4QZLY1Ih/1ukAaabiSNhmazcRMt8s1+Ua7IDmITd eio+R1oRz+pzV8fBInjjTleHgRS2yUPI9U9Hw=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to; bh=A+an3CsCLxWd26AnSrEJ7MqPNCXkCxIApNG5jViBjS0=; b=Tpv83XKWzZoNrC4/rXbDNT14US3oji7JP8KMTIZ00DbtVU/WV9sN5wbxHOmDKk1Jo1 vahq5qjBmS24GHK3KuPpApot6q/vmyRjgkcBKzM7ONG/Jb4DqKy7Ptbt6xp4EWzmvTpB 4EaxrLBWGfJ4J91x3m64BDrtSdpgL2i63/6h0zsnUnZt4/i8MviK0zve+bVbTgdgxfA+ YF4pUdAyXZ7t3Iek4wSaW+YpofVLmYlQAnOFdFNycLavXojiHsInLlJN9Rxp9p+k1X8/ 8z0IvP2XP1my1mAce1CnpiNKkEwLI+/lIj1iW/mJcTAh1Q5thMsEcptNKwFfGm2w9wxL X2eQ==
X-Gm-Message-State: ALKqPwdlYHZOc0DaGTic403YTvqnPlcttx+MD7Wsd6P9PgKTCw1h03KM 9xlmg3rBFQY9GApOmdQb5eM4tg==
X-Google-Smtp-Source: AB8JxZqig9+U3X3DNhDZZxoROoPpWYJhc2XIhDil0FOdg7X4yitmE/8MBHIeO3g7VeeTp0Z6mEEO6Q==
X-Received: by 2002:a6b:d547:: with SMTP id x7-v6mr2529752ioc.50.1527265368551; Fri, 25 May 2018 09:22:48 -0700 (PDT)
Received: from dragon.local ([76.25.3.152]) by smtp.gmail.com with ESMTPSA id x189-v6sm3429433ite.5.2018.05.25.09.22.47 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 25 May 2018 09:22:47 -0700 (PDT)
To: Eric Rescorla <ekr@rtfm.com>
Cc: mls@ietf.org, IESG <iesg@ietf.org>
References: <152630665840.10130.3108627350220292581.idtracker@ietfa.amsl.com> <41fb6ec6-b370-0598-a831-d9a605bbc758@mozilla.com> <CABcZeBMvemAeYhJkbffrWbBW_pxcSzM_xa=U+HwURdz76T1iwA@mail.gmail.com>
From: Peter Saint-Andre <stpeter@mozilla.com>
Openpgp: preference=signencrypt
Autocrypt: addr=stpeter@mozilla.com; prefer-encrypt=mutual; keydata= xsFNBFonEf4BEADvZ+RGsJoOyZaw2rKedB9pBb2nNXVGgymNS9+FAL/9SsfcrKaGYSiWEz7P Lvc97hWH3LACFAHvnzoktv+4IWHjItvhdi9kUQ3Gcbahe55OcdZuSXXH3w5cHF0rKz9aYRpN jENqXM5dA8x4zIymJraqYvHlFsuuPB8rcRIV9SKsvcy14w9iRqu770NjXfE/aIsyRwwmTPiU FQ0fOSDPA/x2DLjed/GYHem90C5vF4Er9InMqH5KAMLnjIYZ9DbPx5c5EME4zW/d648HOvPB bm+roZs4JTHBhjlrTtzDDpMcxHq1e8YPvSdDLPvgFXDcTD4+ztkdO5rvDkbc61QFcLlidU8H 3KBiOVMA/5Rgl4lcWZzGfJBnwvSrKVPsxzpuCYDg01Y/7TH4AuVkv5Na6jKymJegjxEuJUNw CBzAhxOb0H9dXROkvxnRdYS9f0slcNDBrq/9h9dIBOqLhoIvhu+Bhz6L/NP5VunQWsEleGaO 3gxGh9PP/LMyjweDjPz74+7pbyOW0b5VnIDFcvCTJKP0sBJjRU/uqmQ25ckozuYrml0kqVGp EfxhSKVqCFoAS4Q7ux99yT4re2X1kmlHh3xntzmOaRpcZsS8mJEnVyhJZBMOhqE280m80ZbS CYghd2K0EIuRbexd+lfdjZ+t8ROMMdW5L51CJVigF0anyYTcAwARAQABzSdQZXRlciBTYWlu dC1BbmRyZSA8c3RwZXRlckBtb3ppbGxhLmNvbT7CwZQEEwEIAD4WIQQ1VSPTuPTvyWCdvvRl YYwYf2gUqQUCWicR/gIbIwUJCWYBgAULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRBlYYwY f2gUqdaREAChG8qU1853mP0sv2Mersns8TLG1ztgoKHvMXFlMUpNz6Oi6CjjaMNFhP7eUY4T D43+yQs7f4qCkOAPWuuqO8FbNWQ+yUoVkqF8NUrrVkZUlZ1VZBMQHNlaEwwu1CGoHsLoRohP SiZ0hpmGTWB3V6cDDK4KN6nl610WJbzE9LeKY1AxtePdJi2KM281U0Fz8ntij1jWu0gF2xU4 Sez46JDogHLWKgd0srauhcCVzZjAhiWrXp1+ryzSWYaZO8Kh8SnF1f4o6jtYikMqkxUaI5nX wvD3kNX4AMSkCAZfG7Jcfj/SLDojTcREgO87g7B9bcOOsHN4lj3lHoFV0aXpgPmjfIvAjJHu fHkXZAQAH8w0u9bgJqRn703+A4NPfLopnjegyhlNi7fQ3cMQV1H7Oj7WrB/pCcprx+1u/6Uq oTtDwWh1U5uVthVAI0QojpNWR08zABDX19TlGtVoeygaQV3CAEolxTiYQtCfVavUzUplCZ/t 3v4YiRov+NylflJd+1akyOs1IAgARf444BnoH1fotkpfXNOpp9wUXXwsQcFRdP7vpMkSCkc0 sxPNTVX3ei0QImp4NsrFdaep7LV3zEb3wkAp6KE5Qno4hVVEypULbvB0G6twNZbeRfcs2Rjp jnPb2fofvg2WhAKB20dnRfIfK8OKTD/P+JDcauJANjmekM7BTQRaJxH+ARAApPwkbOTChAQu jMvteb/xcwuL5JZElmLxIqvJhqybV7JknM+3ATyN0CTYQFvPTgIrhpk4zSn0A6pEePdK8mKK 5/aHyd7pr7rLEi1sI/X3UE8ld/E83MExksKrYbs0UX1wSQwYXU6g64KicnuP2Abqg+8wrQ18 1nPcZci9jJI75XVPnTdUpZD5aaQWGp7IJ06NTbiOk30I50ORfulgKoe4m3UfsMALFxIx3pJk oy76xC2tjxYGf+4Uq1M0iK3Wy655GrcwXq/5ieODNUcAZzvK5hsUVRodBq0Lq3g1ivQF4ba7 RQayDzlW6XgoeU49xnCr9XdZYnTnj4iaPmr2NtY6AacBwRz+bJsyugeSyGgHsnVGyUSMk8YN wZHvUykMjH21LLzIUX5NFlcumLUXDOECELCJwewui4W81sI5Sq/WDJet+iJwwylUX22TSulG VwDS+j66TLZpk1hEwPanGLwFBSosafqSNBMDVWegKWvZZVyoNHIaaQbrTIoAwuAGvdVncSQz ttC6KkaFlAtlZt3+eUFWlMUOQ9jxQKTWymyliWKrx+S6O1cr4hwVRbg7RQkpfA8E2Loa13oO vRSQy/M2YBRZzRecTKY6nslJo6FWTftpGO7cNcvbmQ6I++5cBG1B1eNy2RFGJUzGh1vlYo51 pdfSg0U1oPHBPCHNvPYCJ7UAEQEAAcLBfAQYAQgAJhYhBDVVI9O49O/JYJ2+9GVhjBh/aBSp BQJaJxH+AhsMBQkJZgGAAAoJEGVhjBh/aBSpAw0P/1tEcEaZUO1uLenNtqysi3mQ6qAHYALR Df3p2z/RBKRVx0DJlzDfDvJ2R/GRwoo+vyCviecuG2RNKmJbf1vSm/QTtbQMUjwut9mx6KCY CyKwniqdhaMBmjCfV2DB2MxxZLYMtDfx/2mY7vzAci7AkjC+RkSUByMEOkyscUydKC/ETdf9 tvI8GhTY/8Q7JSylS3lQA5pMUHiIf+KpSmqKZeBPkGc7nSKM1w1UKUvFAsyyVsiG6A/hWrTr 7tTQAl7YfjtOGE8n4IKGktvrT99bbh9wdWKZ5FdHUN9hx2Q8VP8+0lR1CH2laVFbEwCOv1vM W4cgQDLxwwpo1iOTdHBVtQDxlQ9hPMKVlB1KP9KjchxuiLc24wLmCjP3pDMml4LQxOYB34Eq cgPZ3uHvJZG309sb2wTMTWaXobWNI++ZrsRD5GTmuzF3kkx3krtrq6HI5NSaemxK6MTDTjDN Rj/OwTl0yU35eJXuuryB20GFOSUsxiw00I2hMGQ1Cy9L/+IW6Dvotd8O3LmKh2tFArzXaKLx /rZyGNurS/Go5YjHp8wdJOs7Ka2p1U31js24PMWO6hf6hIiY2WRUsnE6xZNhvBTgKOY6u0KT V6hTevFqEw7OAZDCWUoE2Ob2/oHGZCCMW5SLAMgp7eihF0kGf2S2CmpIFYXGb61hAD8SqSY7 Fn7V
Message-ID: <db43afca-735f-17d1-81c3-70ae868cf9e4@mozilla.com>
Date: Fri, 25 May 2018 10:22:46 -0600
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.8.0
MIME-Version: 1.0
In-Reply-To: <CABcZeBMvemAeYhJkbffrWbBW_pxcSzM_xa=U+HwURdz76T1iwA@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="COrOIJfi64E9eN5WlWM0M59t2HnvfOJDt"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/UB_k91kdU-4tJcqeuy-l4jTDOnI>
Subject: Re: [MLS] [new-work] WG Review: Messaging Layer Security (mls)
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 May 2018 16:22:52 -0000

On 5/24/18 8:05 AM, Eric Rescorla wrote:
> 
> 
> On Mon, May 14, 2018 at 8:55 AM, Peter Saint-Andre <stpeter@mozilla.com
> <mailto:stpeter@mozilla.com>> wrote:
> 
>     Two points:
> 
>     1. It would be helpful to specify the expected capabilities of devices
>     on which the resulting protocol might be deployed, such as only personal
>     devices (e.g., phones and tablets) or also Internet of Things devices.
>     If IoT devices are in scope (I hope they are!), then citing RFC 7228
>     would be good:
> 
>     https://datatracker.ietf.org/doc/rfc7228/
>     <https://datatracker.ietf.org/doc/rfc7228/>
> 
> 
> I think the default is we assume reasonably powerful general purpose
> computers, 

Constrained devices are indeed hard to design for (and there are many
dimensions of constraint - code size, memory, storage, battery, etc.). I
wouldn't necessarily argue for supporting Class 0 devices (which
according to RFC 7228 are "very constrained sensor-like motes"), but
Class 2 devices (which are "fundamentally capable of supporting most of
the same protocol stacks as used on notebooks or servers") would be
great. I'm not sure where to draw the line and whether to include Class
1 devices (which "are quite constrained in code space and processing
capabilities, such that they cannot easily talk to other Internet nodes
employing a full protocol stack such as using HTTP, Transport Layer
Security (TLS), and related security protocols and XML-based data
representations").

> so if people want IoT to be designed for -- which it
> shouldn't, IMO -- then that would have to be stated in the charter.

No matter what we decide, it would be good to make that explicit in the
charter.

Peter