Re: [MMUSIC] Review of draft-ietf-mmusic-sdp-bundle-negotiation-32 - Magnus' comments - MID security

Cullen Jennings <fluffy@iii.ca> Thu, 06 October 2016 21:59 UTC

Return-Path: <fluffy@iii.ca>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDA851297C9 for <mmusic@ietfa.amsl.com>; Thu, 6 Oct 2016 14:59:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.621
X-Spam-Level:
X-Spam-Status: No, score=-2.621 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W7GHCf6wjLkz for <mmusic@ietfa.amsl.com>; Thu, 6 Oct 2016 14:59:14 -0700 (PDT)
Received: from smtp130.dfw.emailsrvr.com (smtp130.dfw.emailsrvr.com [67.192.241.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2BE671297C6 for <mmusic@ietf.org>; Thu, 6 Oct 2016 14:59:14 -0700 (PDT)
Received: from smtp17.relay.dfw1a.emailsrvr.com (localhost [127.0.0.1]) by smtp17.relay.dfw1a.emailsrvr.com (SMTP Server) with ESMTP id 4A408201E9; Thu, 6 Oct 2016 17:59:13 -0400 (EDT)
X-Auth-ID: fluffy@iii.ca
Received: by smtp17.relay.dfw1a.emailsrvr.com (Authenticated sender: fluffy-AT-iii.ca) with ESMTPSA id C19E020184; Thu, 6 Oct 2016 17:59:12 -0400 (EDT)
X-Sender-Id: fluffy@iii.ca
Received: from [192.168.4.100] ([UNAVAILABLE]. [128.107.241.185]) (using TLSv1 with cipher DHE-RSA-AES256-SHA) by 0.0.0.0:465 (trex/5.7.7); Thu, 06 Oct 2016 17:59:13 -0400
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Cullen Jennings <fluffy@iii.ca>
In-Reply-To: <71419d1f-af1d-46e9-401d-81c5df73fc49@ericsson.com>
Date: Thu, 06 Oct 2016 15:59:11 -0600
Content-Transfer-Encoding: quoted-printable
Message-Id: <58510E68-A045-4312-B3B3-3468E83C8EB7@iii.ca>
References: <D41C238A.1095B%christer.holmberg@ericsson.com> <71419d1f-af1d-46e9-401d-81c5df73fc49@ericsson.com>
To: Magnus Westerlund <magnus.westerlund@ericsson.com>
X-Mailer: Apple Mail (2.3124)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/WIF3VZT1Z6nrEA_vxhj5m7drW6w>
Cc: "mmusic@ietf.org" <mmusic@ietf.org>, Paul Kyzivat <pkyzivat@alum.mit.edu>, Christer Holmberg <christer.holmberg@ericsson.com>
Subject: Re: [MMUSIC] Review of draft-ietf-mmusic-sdp-bundle-negotiation-32 - Magnus' comments - MID security
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Oct 2016 21:59:17 -0000

I'm not getting the problem here and mandating 6904 is not an easy thing to do.

I'm not getting what the issue is here. If mid are random, or are just a count of n'th m-line in the sdp, what is the problem with exposing them to people are getting the media?



> On Oct 6, 2016, at 7:39 AM, Magnus Westerlund <magnus.westerlund@ericsson.com> wrote:
> 
> Den 2016-10-06 kl. 14:49, skrev Christer Holmberg:
>> 
>> Hi,
>> 
>> Magnus suggested usage of RFC 6904 for encryption of the RTP SDES header
>> extension for MID. I guess it would be a SHUOLD?
>> 
>> In addition, we would say that a corresponding level of security must be
>> applied to the RTP SDES header extension for MID and to the RTCP SDES MID
>> item.
>> 
>> Any opinions?
> 
> I think this is fine solution to this issue. I would probably formulate the security considerations like this.
> 
> The identfication-tag when included in the RTP MID SDES item, independent of transport, RTCP SDES packet or RTP header extension, can expose the value to parties beyond the signaling chain. Therefore, the identification-tag MUST NOT contain any user related information. However, the implementation's method for generating identfication-tags combined with hardware configuration can enable fingerprinting of the endpoint device and thus its user. As the identification-tag is also used to route the media stream to the right application functionality it is also important that the value received is the one intended by the sender, thus integrity and the authenticity of the source are important to prevent denial of service on the application. At least to prevent third parties from modifying the identification-tag value.
> 
> Due to the security risks associated with the MID values in RTP and RTCP it is strongly RECOMMENDED that the MID SDES item is both confidentiality protected as well as source authenticated when transported in either RTCP or RTP header extensions. The security mechanisms used SHALL provide corresponding levels of security for both RTP header extensions and RTCP. Confidentiality mechanisms for RTP/RTCP are discussed in Options for Securing RTP Sessions [RFC7201], for example SRTP [RFC3711] with SRTCP encryption enabled combined with [RFC6904] can provide the necessary security functions.
> 
> 
> Cheers
> 
> Magnus Westerlund
> 
> ----------------------------------------------------------------------
> Services, Media and Network features, Ericsson Research EAB/TXM
> ----------------------------------------------------------------------
> Ericsson AB                 | Phone  +46 10 7148287
> Färögatan 6                 | Mobile +46 73 0949079
> SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
> ----------------------------------------------------------------------
> 
> _______________________________________________
> mmusic mailing list
> mmusic@ietf.org
> https://www.ietf.org/mailman/listinfo/mmusic