Re: [MMUSIC] [rtcweb] [tram] TURN permissions for private ips

Emil Ivov <emcho@jitsi.org> Fri, 07 August 2015 00:12 UTC

Return-Path: <emcho@sip-communicator.org>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA1D51A1BB9 for <mmusic@ietfa.amsl.com>; Thu, 6 Aug 2015 17:12:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.979
X-Spam-Level:
X-Spam-Status: No, score=-1.979 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o2dwTLoms2-r for <mmusic@ietfa.amsl.com>; Thu, 6 Aug 2015 17:12:14 -0700 (PDT)
Received: from mail-ob0-f178.google.com (mail-ob0-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0A7D21A1B51 for <mmusic@ietf.org>; Thu, 6 Aug 2015 17:12:13 -0700 (PDT)
Received: by obnw1 with SMTP id w1so67948147obn.3 for <mmusic@ietf.org>; Thu, 06 Aug 2015 17:12:13 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=Pxr/LuCD3rDOKSXP/EZUedVgPCzhxZ3Q6hpeb/ktcdk=; b=L8qtSQTDYOX0JaSUv40NTuMyALdYjACC9flcgYDYmhA3QbaRu3uHmnwzhrnWZDOCUA +TMjswyegNq/ZFBhv9RgHRAY+XUQ0ZQKQQAcImj/VWdLCOwtXhiYcoi47ZooXGSsRBLt U3I0MF/9CF472cbRRL8B5FOkdTX/Gy1KqXNzndEv9dPR4m7wnjEhRfSu38MuRbYKzTOo pwt5cXFnpBQmT++fze+FhgLSCkmstghFWb49RqawEXo/apWyyOIrzvl88b5QsA+SsUyo 6PmR5QEAVJZ+W5mFdGnGORd5qd3CSGVG+F7D2+pBGgRKU+b+lBOpT24ZEIMlreKS913W mdJA==
X-Gm-Message-State: ALoCoQkOIU0U9tvnTvLJHfQvss67qMPEqf1OfAdys+2CMENnp5NkiwY5OhHiAkWtYDxUkSSKCvA+
X-Received: by 10.60.177.73 with SMTP id co9mr4059697oec.5.1438906333316; Thu, 06 Aug 2015 17:12:13 -0700 (PDT)
Received: from mail-ob0-f176.google.com (mail-ob0-f176.google.com. [209.85.214.176]) by smtp.gmail.com with ESMTPSA id de16sm4917081oec.6.2015.08.06.17.12.12 for <mmusic@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 06 Aug 2015 17:12:12 -0700 (PDT)
Received: by obbop1 with SMTP id op1so68160875obb.2 for <mmusic@ietf.org>; Thu, 06 Aug 2015 17:12:12 -0700 (PDT)
X-Received: by 10.182.213.227 with SMTP id nv3mr4094704obc.10.1438906332349; Thu, 06 Aug 2015 17:12:12 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.76.83.167 with HTTP; Thu, 6 Aug 2015 17:11:52 -0700 (PDT)
In-Reply-To: <CAOJ7v-2PaLr8XLdVxfPY=YYzeQuoj49qypUTUr=wdbmSiMZO7A@mail.gmail.com>
References: <20150805130607.20844.70680.idtracker@ietfa.amsl.com> <CABcZeBMWVU9a1_e_47qddA04WhXG55QYzFA=dTrYgi+DuLQhKA@mail.gmail.com> <55C24293.5000603@cs.tcd.ie> <55C24C09.8020404@goodadvice.pages.de> <55C256C8.80606@jive.com> <CAOJ7v-3hyFhHiFq4eujLznXtehkUSxZati8YZ23o-RPLH=J5zg@mail.gmail.com> <F144FF61-AAC6-4E0A-B08E-0E3F9B487F1B@vidyo.com> <CAOJ7v-0Z4fmWjVaeiAJh=rpYPjUsk_k8_=g8CrecAZQWtRG1AQ@mail.gmail.com> <CABkgnnXubczrXpR+YHeF1+zNrNoPNMH_XdB1+pCAGZ9LQn0UXw@mail.gmail.com> <CAOJ7v-2PaLr8XLdVxfPY=YYzeQuoj49qypUTUr=wdbmSiMZO7A@mail.gmail.com>
From: Emil Ivov <emcho@jitsi.org>
Date: Thu, 06 Aug 2015 17:11:52 -0700
Message-ID: <CAPvvaaK9xxxfmVOjE_UtX_Z6RzLe3RjR-Q=55F_Mp-9X1Li0Sg@mail.gmail.com>
To: Justin Uberti <juberti@google.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/mmusic/L6QTMgg_TKCxqGZD-wpIOTFxRKs>
Cc: Jonathan Lennox <jonathan@vidyo.com>, mmusic <mmusic@ietf.org>, "tram@ietf.org" <tram@ietf.org>, "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [MMUSIC] [rtcweb] [tram] TURN permissions for private ips
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Aug 2015 00:12:16 -0000

On Thu, Aug 6, 2015 at 5:01 PM, Justin Uberti <juberti@google.com> wrote:
>
>
> On Thu, Aug 6, 2015 at 1:51 PM, Martin Thomson <martin.thomson@gmail.com>
> wrote:
>>
>> On 6 August 2015 at 13:08, Justin Uberti <juberti@google.com> wrote:
>> > I think that we should be able to avoid pairing candidates obtained from
>> > application TURN servers with RFC 1918 addresses. The app/browser
>> > clearly
>> > knows which is which.
>>
>> I'm concerned here that if we let the application choose, we lose the
>> defence we were looking to gain.  I think that perhaps 1918 pairing
>> could be restricted to TURN servers that are configured/discovered,
>> "proxy"-style.
>
>
> Sorry, that is what I was trying to say. The browser knows which turn
> servers are "proxies" vs app servers, and can apply the 1918 filtering on
> the pairings from the candidates from the app TURN server.

I don't think Jonathan's concerns only apply to proxies though. You
can just as well have apps developed for specific networks and there
is no reason to prevent those from working.

> Agree with your enumeration of concerns as well. Also #5, they consume
> bandwidth (at least from client to TURN server), which affects maximum check
> rate in some cases.

Why can't we address this by TURN servers simply refusing to create
permissions for candidates they know they won't be able to reach?

Emil

-- 
https://jitsi.org