Re: [MMUSIC] Handling of unverified data and media
Peter Thatcher <> Thu, 30 March 2017 19:14 UTC
Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 512F1126B6D for <>; Thu, 30 Mar 2017 12:14:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id tJoj0np3gt2B for <>; Thu, 30 Mar 2017 12:14:40 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:400d:c09::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 02D16126B72 for <>; Thu, 30 Mar 2017 12:14:39 -0700 (PDT)
Received: by with SMTP id d201so19156617qkc.0 for <>; Thu, 30 Mar 2017 12:14:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Y98aApw3WqICzHZ0C9UODhP9r36V3IXoXMJTgbrY7Lk=; b=Om6ZkRmRrdqW3mImAf7FznN04+OwrCsIDjpW4pWduUP+H3OFWsRdVQF50wDWO62ZXp 47kaQWONusd4KW8jBCWKQ2pR45oZe6AKjThn6V8oKV0vyk3nbfvjtHa4n9lRVzMZujii 6sJ0jn43x/Ewvf5N2UTx2fBF1Rm5oS12KW4gTPPuppKQdI1PCtF4crV8hT4tCPuvNQia qXn4WLZN6abzn8A2WBfSDQfGG3YWsXEQCrVku3OPRprEi7e0WjAW2dQ+mHoZVCaimS2S lJNFXgdgjlTCbpB93kMsO1c2EnWlf9powwWy5gbb9tu2oGp/zHAq/yCOmVl+2nYzjUDf 0r/Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Y98aApw3WqICzHZ0C9UODhP9r36V3IXoXMJTgbrY7Lk=; b=FTNr2CaE+cdfNeKnjenRLTVdCOJaAzcdxQDTT/EjDA0fmpyYpBCEMbInL+DgxVuwH9 pYSQLdnt0k7AD5ziyIxuEx5DJGYrXkuKosPXvzm4MyGLX1Y63sl1/JWVZ/E2jRrqQ33K uP+aO/XhI3OvuwfHZWjcnwSuOTXhttKFcvsKNK5cMe+qT/tVAQ+R/cn6qh8sjQv9yDpN rKenEFcuGawTeDS7jFhIs9P5biLqDgc3ZBdnNb4TWjsQmALQLmMHer4neqyyS+nwFt/o 3O31OAvSuk1nyeMF3Ed47hl1vPyXNzS+fZ2WmTIdPB0PE1DzAEm40T/OkyoU0VNFSTn1 SOJQ==
X-Gm-Message-State: AFeK/H15JQP9fA5xdGPYVLnfpQ0a1hvFhZpl0eo1I8qgyV6I97YDkbBjKgSp5RVKUgiO+LiT5C8INqCX4jDMuYX6
X-Received: by with SMTP id h127mr1430002qkf.121.1490901277726; Thu, 30 Mar 2017 12:14:37 -0700 (PDT)
MIME-Version: 1.0
References: <> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
From: Peter Thatcher <>
Date: Thu, 30 Mar 2017 19:14:26 +0000
Message-ID: <>
To: Cullen Jennings <>, Christer Holmberg <>
Cc: mmusic <>
Content-Type: multipart/alternative; boundary="94eb2c0600560e4ed3054bf781aa"
Archived-At: <>
Subject: Re: [MMUSIC] Handling of unverified data and media
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Thu, 30 Mar 2017 19:14:42 -0000
We have a mailing list discussion (here), a bug ( and a PR ( about this. I've copied the following comments to the latter two, so I'm adding them here as well. TL;DR: I don't think unverified media is compatible with ICE+DTLS. Here is why (you can go see the bug, too): 1. You can *receive* DTLS from the remote side before receiving the remote description (and thus fingerprint). This happens if the remote side sends an ICE connectivity check and the local side sends a response and then the remote side sends a DTLS packet. 2. You cannot *send* DTLS from the local side before receiving the remote description (and thus fingerprint). This is because you can't send an ICE connectivity check until you have the remote ICE ufrag and pwd, and thus can't get an ICE connectivity check response, and thus can't send DTLS. This is because you can't send anything other than ICE until you get an ICE connectivity check response. 3. Since you can't send DTLS, you can't complete the handshake, and thus can't extract the SRTP key. Maybe I'm missing something, but I think this is impossible. On Sat, Mar 25, 2017 at 1:12 PM Cullen Jennings <> wrote: > > On Mar 13, 2017, at 3:44 PM, Christer Holmberg < >> wrote: > > My question is: is this something that’s causing problems in real > deployments, and requires a change in the standard? > > > 1-800 go fedex. See webrtc requirements documents from many years ago. > _______________________________________________ > mmusic mailing list > > >
- [MMUSIC] Handling of unverified data and media Bernard Aboba
- Re: [MMUSIC] Handling of unverified data and media Martin Thomson
- Re: [MMUSIC] Handling of unverified data and media Roman Shpount
- Re: [MMUSIC] Handling of unverified data and media Eric Rescorla
- Re: [MMUSIC] Handling of unverified data and media Bernard Aboba
- Re: [MMUSIC] Handling of unverified data and media Eric Rescorla
- Re: [MMUSIC] Handling of unverified data and media Christer Holmberg
- Re: [MMUSIC] Handling of unverified data and media Iñaki Baz Castillo
- Re: [MMUSIC] Handling of unverified data and media Christer Holmberg
- Re: [MMUSIC] Handling of unverified data and media Iñaki Baz Castillo
- Re: [MMUSIC] Handling of unverified data and media Christer Holmberg
- Re: [MMUSIC] Handling of unverified data and media Cullen Jennings
- Re: [MMUSIC] Handling of unverified data and media Martin Thomson
- Re: [MMUSIC] Handling of unverified data and media Jonathan Lennox
- Re: [MMUSIC] Handling of unverified data and media Roman Shpount
- Re: [MMUSIC] Handling of unverified data and media Christer Holmberg
- Re: [MMUSIC] Handling of unverified data and media Jonathan Lennox
- Re: [MMUSIC] Handling of unverified data and media Christer Holmberg
- Re: [MMUSIC] Handling of unverified data and media Cullen Jennings
- Re: [MMUSIC] Handling of unverified data and media Peter Thatcher
- Re: [MMUSIC] Handling of unverified data and media Martin Thomson
- Re: [MMUSIC] Handling of unverified data and media Bernard Aboba
- Re: [MMUSIC] Handling of unverified data and media Martin Thomson
- Re: [MMUSIC] Handling of unverified data and media Peter Thatcher
- Re: [MMUSIC] Handling of unverified data and media Roman Shpount
- Re: [MMUSIC] Handling of unverified data and media Cullen Jennings
- Re: [MMUSIC] Handling of unverified data and media Cullen Jennings
- Re: [MMUSIC] Handling of unverified data and media Martin Thomson
- Re: [MMUSIC] Handling of unverified data and media Peter Thatcher
- Re: [MMUSIC] Handling of unverified data and media Roman Shpount
- Re: [MMUSIC] Handling of unverified data and media Peter Thatcher