Re: [MMUSIC] [rtcweb] [tram] TURN permissions for private ips

Martin Thomson <martin.thomson@gmail.com> Thu, 06 August 2015 20:51 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B23081B32FA; Thu, 6 Aug 2015 13:51:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cgvXOTimBOyS; Thu, 6 Aug 2015 13:51:52 -0700 (PDT)
Received: from mail-lb0-x234.google.com (mail-lb0-x234.google.com [IPv6:2a00:1450:4010:c04::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 131B71B32FC; Thu, 6 Aug 2015 13:51:52 -0700 (PDT)
Received: by lbbyj8 with SMTP id yj8so49857617lbb.0; Thu, 06 Aug 2015 13:51:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=WB6o88qL/fXEOLZiSFomzUP+RsoPUgYwLUgic+aeQVU=; b=olEqV7g+1nJUAikCBdfcIfm3+V6J0bpa356buWsvAGBA8hweeE9Ohm1IXh0ZsbSJ0j TVLOh+m1T0Q8vwFYXWs2ipDbV3/kI7GzDhGTlXd2rsY1YORmqwf7fFgFK9aIFSa0O/tX sfwN3S5BjkSVJsFqRHuG1YRLlrhDI0735nbxQTg+mQJM0Kc/rteuguNtgqxz3159BTK8 BkRKtf4FgQDvuPtq+IYbtpJpfBVp7/skNGNgQETmNr0w1PSwU0b3PKd4ZZLh1Jyk6/sO QZlRG0dUPqPM4z8tQbEmxROVjxxxo89eHJlZpEnfUfgHAdfWCrwCWwjbbJLVDPYdWcoF BSBw==
MIME-Version: 1.0
X-Received: by 10.152.179.42 with SMTP id dd10mr4233835lac.89.1438894310528; Thu, 06 Aug 2015 13:51:50 -0700 (PDT)
Received: by 10.25.197.87 with HTTP; Thu, 6 Aug 2015 13:51:50 -0700 (PDT)
In-Reply-To: <CAOJ7v-0Z4fmWjVaeiAJh=rpYPjUsk_k8_=g8CrecAZQWtRG1AQ@mail.gmail.com>
References: <20150805130607.20844.70680.idtracker@ietfa.amsl.com> <CABcZeBMWVU9a1_e_47qddA04WhXG55QYzFA=dTrYgi+DuLQhKA@mail.gmail.com> <55C24293.5000603@cs.tcd.ie> <55C24C09.8020404@goodadvice.pages.de> <55C256C8.80606@jive.com> <CAOJ7v-3hyFhHiFq4eujLznXtehkUSxZati8YZ23o-RPLH=J5zg@mail.gmail.com> <F144FF61-AAC6-4E0A-B08E-0E3F9B487F1B@vidyo.com> <CAOJ7v-0Z4fmWjVaeiAJh=rpYPjUsk_k8_=g8CrecAZQWtRG1AQ@mail.gmail.com>
Date: Thu, 06 Aug 2015 13:51:50 -0700
Message-ID: <CABkgnnXubczrXpR+YHeF1+zNrNoPNMH_XdB1+pCAGZ9LQn0UXw@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
To: Justin Uberti <juberti@google.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/mmusic/fREeo67w13hxQFi-fD4ZPY52oQs>
Cc: Jonathan Lennox <jonathan@vidyo.com>, "rtcweb@ietf.org" <rtcweb@ietf.org>, "tram@ietf.org" <tram@ietf.org>, mmusic <mmusic@ietf.org>
Subject: Re: [MMUSIC] [rtcweb] [tram] TURN permissions for private ips
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Aug 2015 20:51:53 -0000

On 6 August 2015 at 13:08, Justin Uberti <juberti@google.com> wrote:
> I think that we should be able to avoid pairing candidates obtained from
> application TURN servers with RFC 1918 addresses. The app/browser clearly
> knows which is which.

I'm concerned here that if we let the application choose, we lose the
defence we were looking to gain.  I think that perhaps 1918 pairing
could be restricted to TURN servers that are configured/discovered,
"proxy"-style.