Re: [MMUSIC] The floodgates are open

Bernard Aboba <bernard_aboba@hotmail.com> Sat, 13 October 2012 00:43 UTC

Return-Path: <bernard_aboba@hotmail.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3953B21F84F1 for <mmusic@ietfa.amsl.com>; Fri, 12 Oct 2012 17:43:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.901
X-Spam-Level:
X-Spam-Status: No, score=-101.901 tagged_above=-999 required=5 tests=[AWL=-0.697, BAYES_00=-2.599, MIME_QP_LONG_LINE=1.396, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PQ8uBWO+bxO2 for <mmusic@ietfa.amsl.com>; Fri, 12 Oct 2012 17:43:41 -0700 (PDT)
Received: from blu0-omc4-s26.blu0.hotmail.com (blu0-omc4-s26.blu0.hotmail.com [65.55.111.165]) by ietfa.amsl.com (Postfix) with ESMTP id 91CBA21F84D4 for <mmusic@ietf.org>; Fri, 12 Oct 2012 17:43:41 -0700 (PDT)
Received: from BLU402-EAS111 ([65.55.111.135]) by blu0-omc4-s26.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Fri, 12 Oct 2012 17:43:40 -0700
X-Originating-IP: [72.11.69.66]
X-EIP: [pBJr4Nv92mSSMD3dl9Q7TGSkJlwo0ZK2]
X-Originating-Email: [bernard_aboba@hotmail.com]
Message-ID: <BLU402-EAS111872991D73BA79867F64893730@phx.gbl>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
References: <CABkgnnWSTDok4-48g-vFGM_zk0ykU-BvrOWfpffAfJeZd41EGA@mail.gmail.com> <CA+9kkMDau2CtFLUq34w1FZrX-MqcVqLV=3PTtfGSFFosBN_5CA@mail.gmail.com>
From: Bernard Aboba <bernard_aboba@hotmail.com>
MIME-Version: 1.0 (1.0)
In-Reply-To: <CA+9kkMDau2CtFLUq34w1FZrX-MqcVqLV=3PTtfGSFFosBN_5CA@mail.gmail.com>
Date: Fri, 12 Oct 2012 17:44:25 -0700
To: Ted Hardie <ted.ietf@gmail.com>
X-OriginalArrivalTime: 13 Oct 2012 00:43:40.0858 (UTC) FILETIME=[CA4731A0:01CDA8DB]
Cc: "mmusic@ietf.org" <mmusic@ietf.org>
Subject: Re: [MMUSIC] The floodgates are open
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mmusic>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 13 Oct 2012 00:43:42 -0000

A receiver can stop responding to STUN binding requests. However, this will take a while to take effect and it is all or nothing.  With a sender-based congestion control scheme there may not be a way for the receiver to indicate a limit, and even in a receiver-based scheme TMMBR messages aren't acknowledged.

On Oct 12, 2012, at 16:25, "Ted Hardie" <ted.ietf@gmail.com> wrote:

> So, possibly I am completely misunderstanding the state of play here,
> but I thought that we had come to the understanding that ICE gave you
> a boolean consent *for the length of the consent freshness*  (and that
> we could (n theory, at least alter the length of the consent freshness
> to handle the risk of voice-hammer style attacks).  In other words,
> that boolean exposes you to risk only for the time of the consent
> freshness, not for all time, and this mitigated the risk sufficiently.
> 
> What have I missed?
> 
> Ted
> 
> On Fri, Oct 12, 2012 at 2:59 PM, Martin Thomson
> <martin.thomson@gmail.com> wrote:
>> The consent that ICE provides is strictly Boolean.
>> 
>> There is no way to distinguish between consent to receive 4kbps audio
>> and 5Mbps video.  This creates an exposure for services and endpoints
>> that support receipt of media, in particular contact centres and other
>> services that are necessarily open to incoming sessions by default.
>> 
>> This working group has an analogous problem.  The consent to entertain
>> modifications to ICE did not stipulate any constraints on volume.
>> Looking to exploit that shortcoming, Bernard and I have submitted a
>> draft that addresses the protocol shortcoming:
>> 
>> http://tools.ietf.org/html/draft-thomson-mmusic-rtcweb-bw-consent-00
>> _______________________________________________
>> mmusic mailing list
>> mmusic@ietf.org
>> https://www.ietf.org/mailman/listinfo/mmusic
> _______________________________________________
> mmusic mailing list
> mmusic@ietf.org
> https://www.ietf.org/mailman/listinfo/mmusic