Re: [MLS] Federation and MLS

Leif Johansson <leifj@mnt.se> Tue, 26 March 2019 08:39 UTC

Return-Path: <leifj@mnt.se>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9062120295 for <mls@ietfa.amsl.com>; Tue, 26 Mar 2019 01:39:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mnt-se.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H-sSI9J0OggZ for <mls@ietfa.amsl.com>; Tue, 26 Mar 2019 01:39:20 -0700 (PDT)
Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 27388120284 for <mls@ietf.org>; Tue, 26 Mar 2019 01:39:20 -0700 (PDT)
Received: by mail-wm1-x32e.google.com with SMTP id a188so11840644wmf.3 for <mls@ietf.org>; Tue, 26 Mar 2019 01:39:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnt-se.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=hs76tINOdCokRaMYwAIpaFE0kBAi1nFIPte0MjD6iKY=; b=RkQPhX2beLc66ni+44vvV0nE3UhE63NZGbf6GsHbGvElDkHkV55uagQKJZgzPX70bs 9ro4Krlx1SBfjBaoJTq/ruUwIe1FKCAbLRdUEYVPWFE0imId7GZm/PfB60WWJo/1a/Dr a/AG7wNeDdADB9lQ1lquHuIBus1ffSpCkrkKBfELbfVCbTPXcCwTSxjCSB4M6nshjXHA S7EiJ58kYaRiGRcO20YmpYF+OMiL44UoXUmy6LKRvMqmy0DeSUfrLuelmv1/N6AoX/MJ xPUjqZTKuHsubDDHZLrthNjWt2Ny65A+0b9Pu5Y4ofARx5B6NtcSnyI8HoufOm7EJVvS N08A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=hs76tINOdCokRaMYwAIpaFE0kBAi1nFIPte0MjD6iKY=; b=pLdzERqzNx2hCzkwkT48xQkxociO44iOZqGlg8LgJy3XZhjWgbHf1eK09k+LvkR3ah Y8i/8NMQsMu9HcG931ZPIBWohmJB//WUiPmAA2gmDCfo4x8l8qQJTQa0G88RWC4Fnk/E VRZQUNbWpgAUBe5DSh68yPdkzbyiTKLFQT7ZGzldy8/WndyYGGx+JmE3IqQZOG3sUF0U lNtpAXWCXfD+AKUeoAqO6kX+n2cqVZXpszyu/RJkuojg8uy6EUi4r598QJnz7FKuoZ+G 4oG4datp9AcFz5BVLjRNYZ7rrNmxxvTS5jtcdodXRyQFlSb9Eq1Z+E1kfZUFb+zwTkAT 59yg==
X-Gm-Message-State: APjAAAUkNwatp99Weq4WUj8jw3W6WoMijzjV6SF4ia7/dSXm72+J6feO kZjn0Gml9bVmebLF/r/l3g5f2CmacQ/wKg==
X-Google-Smtp-Source: APXvYqx8Y6w3svrmfhuxBXvXUp/DyfUHzf9TNjPWr6sL6Z5zr3rGbeuZ4Il59PIWSfLr8RQ60R0XtQ==
X-Received: by 2002:a7b:c767:: with SMTP id x7mr8722952wmk.6.1553589558138; Tue, 26 Mar 2019 01:39:18 -0700 (PDT)
Received: from ?IPv6:2001:67c:370:128:b149:a3b1:7bc2:d1be? ([2001:67c:370:128:b149:a3b1:7bc2:d1be]) by smtp.gmail.com with ESMTPSA id w16sm22151473wrt.84.2019.03.26.01.39.16 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 26 Mar 2019 01:39:17 -0700 (PDT)
To: mls@ietf.org
References: <817649924.1176598.1553527876075.JavaMail.zimbra@inria.fr> <CAHo7dC913xSx-5ZaFkJ7_ZRQJyV31NO3OBSFJ2FNJ42mFdy1hQ@mail.gmail.com>
From: Leif Johansson <leifj@mnt.se>
Openpgp: preference=signencrypt
Autocrypt: addr=leifj@mnt.se; prefer-encrypt=mutual; keydata= mQGiBD7DfnwRBADpIpOw6bXfx2Yo3vac/j5WzVcWNZKuiYc4uuFnBYxH8zTA5cdwytuOYNte cX1yrPgmObfPVU0EFktdBMFgLE5TNRUMeJZTmAl3QYDm8N32SeSUEb6GPFsUTGgxsCW3GVAo q6DBopKqhR9HT0+crQakbc7XkS4FjeBWiXjuNf/IqwCgyoa2Qfq8UdjbcH+DRGzPnRTeqzEE ALIEsCzDp4HQqXqqNLCoExbgmCrEHvnqFmilCHJVnyuY8LXmcpq2uwJaiIdsTqLeQ8WrMxWg mZc6F9QSdLP6MVZT3v+5OqOZMUDsu4nGom3HH+tG238vMSEF+klGdrI0wdscrY+28Oshjhqj 4FZxCwdNU9RTU8xQ9IoObiEo1yOHBADK9a5GhkLT+d2cb48orETGtG7i//HOnstouw/TmEUX reZPtT6wpIdN9Jf3W80GA6A34VEGA/I+/5e+9nFvINpLvEF2ghJBH+sWwQ8EXpo0M/yir9oG eJI7gpOHRj5Mq9uqFG0wcamInuWgbMP1cefjXusHbHyDFKr7ydWSsZHqXrQdTGVpZiBKb2hh bnNzb24gPGxlaWZqQG1udC5zZT6IYAQTEQIAIAUCSnC8wwIbIwYLCQgHAwIEFQIIAwQWAgMB Ah4BAheAAAoJEPCcfBbWzGZ3x8MAnimIMTFOH4LLfp8bQnSPWm6BQyA6AKCk4S46++PpqtTM 0wIZ+kuYaBtky7kCDQQ+w36FEAgAr1zK1qIIXmoeEqFulgFi17FRpSibNwwge9bkG2+IO7MO m4Ih+f4CRkqaP5U5diiWb4nyQc/Yqzf3TTSE+CH0ghvDCwfZHrzUsVl9t57S2RFKaQhDUUw3 lz0TgKN66z1IRnQEARuz9PFd96pIhLaJBOn0e55Cu5qqJVwGpst3+I3jqT/cxjymRxPz2O6R 9k/ZOOiOGROZYAjNHKcdoeBr7OaIHcPRCi1R8MBKE4HOK1SwaVvs26Fd2enixIOBmyFTkrue 3VgaAd3zrJauD0qa/u5y2kGEyFFJwNsKnoX0aCmNNIG+aKvnSCWfba8bmYOAsbxS2lo4MKmu DM0rrVyLhwADBQf/VzM77aviZ3Ir7qXj0uV/62wyrg8/5flXl8XjuATewD+hTaux1lg5LgPU 9cokMHYHrTsnp79nhEB9qOpsQLX+npae7a27x3zyqLP0V7neyKy1ycuBI9KU9B3ivgSMRlKR 91GcmUpRnKiSnxPYNtq018mY72YYHCpfAh0OOUA88bxbYIuF5cv9dYyOBhNEkI8xB1VOWev1 CPkPb0DwDABHdOBq9e0hT3OUOaat2JPwCEHU2NTGsYFuZRysq8xnxFgHd00+h2OJZ50UYVpB jDxaCj5gvHHFFnmfCLD5VqjEJGi4k2znZHg67i2pw0f5BSq8fsfdUML35LzL/aaZPMzlg4hG BBgRAgAGBQI+w36FAAoJEPCcfBbWzGZ3djcAnAxF3084vKlsRNGcyj/rn5lA4Q+nAKCnjZYX snFG51wbu8OI88aj3LJE5w==
Message-ID: <06ed3028-3044-0e10-dd44-caf50496d3b7@mnt.se>
Date: Tue, 26 Mar 2019 09:39:16 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.5.1
MIME-Version: 1.0
In-Reply-To: <CAHo7dC913xSx-5ZaFkJ7_ZRQJyV31NO3OBSFJ2FNJ42mFdy1hQ@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/rQEY8nLzbtzIAlPvRaFDx4WQACA>
Subject: Re: [MLS] Federation and MLS
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Mar 2019 08:39:24 -0000

>     3) Metadata:
> 
>     In general, some sort of metadata will need to be shared, i.e.
>     icons,  human readable user-names, group names. I would suggest that
>     as this may be an application message that is simply be considered a
>     non-cryptographic update. Any attempt to proscibe too much on this
>     layer leads to endless bike-shedding and so should be avoided :)
>     However, some minimal optional subset of metadata commonly used for
>     chat could be useful, but rather than whiteboard it, it would be
>     better to have each major MLS vendor that plans to support
>     federation see what their common subset is with everyone else, and
>     then just make a call that delivers just that as an MLS update. 
> 
> I think this will be up to the application  layer, MLS shouldn't care
> about this.
Won't this lead to spoofing-oportunities? Users will place trust in
the the artifacts that are presented to them (names, icons etc) which
means that in general such artifacts should be as tightly bound to keys
as any properties tied to the user that are designed to be used by the
protocol.

	Cheers Leif