Re: [ntpwg] Antw: Re: Antw: Re: call for adoption (draft-dfranke-ntp-data-minimization)
Harlan Stenn <stenn@nwtime.org> Tue, 28 March 2017 23:23 UTC
Return-Path: <ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org>
X-Original-To: ietfarch-ntp-archives-ahFae6za@ietfa.amsl.com
Delivered-To: ietfarch-ntp-archives-ahFae6za@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A625F126BFD for <ietfarch-ntp-archives-ahFae6za@ietfa.amsl.com>; Tue, 28 Mar 2017 16:23:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YPqqSvsybks9 for <ietfarch-ntp-archives-ahFae6za@ietfa.amsl.com>; Tue, 28 Mar 2017 16:23:19 -0700 (PDT)
Received: from lists.ntp.org (psp3.ntp.org [185.140.48.241]) by ietfa.amsl.com (Postfix) with ESMTP id 562A5129542 for <ntp-archives-ahFae6za@lists.ietf.org>; Tue, 28 Mar 2017 16:23:19 -0700 (PDT)
Received: from psp3.ntp.org (localhost.ntp.org [127.0.0.1]) by lists.ntp.org (Postfix) with ESMTP id E73A286DC2C for <ntp-archives-ahFae6za@lists.ietf.org>; Tue, 28 Mar 2017 23:23:18 +0000 (UTC)
X-Original-To: ntpwg@lists.ntp.org
Delivered-To: ntpwg@lists.ntp.org
Received: from mail1.ntp.org (fortinet.ntp.org [10.224.90.254]) by lists.ntp.org (Postfix) with ESMTP id 16D3D86DAE6 for <ntpwg@lists.ntp.org>; Tue, 28 Mar 2017 23:23:15 +0000 (UTC)
Received: from chessie.everett.org ([66.220.13.234]) by mail1.ntp.org with esmtps (TLSv1:CAMELLIA256-SHA:256) (Exim 4.77 (FreeBSD)) (envelope-from <stenn@nwtime.org>) id 1ct0SB-0006FO-AR for ntpwg@lists.ntp.org; Tue, 28 Mar 2017 23:23:15 +0000
Received: from localhost (localhost [127.0.0.1]) by chessie.everett.org (Postfix) with SMTP id 3558AB835 for <ntpwg@lists.ntp.org>; Tue, 28 Mar 2017 23:23:06 +0000 (UTC)
Received: from [192.168.1.19] (97-90-117-231.dhcp.mdfd.or.charter.com [97.90.117.231]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by chessie.everett.org (Postfix) with ESMTPSA id C32EBB825 for <ntpwg@lists.ntp.org>; Tue, 28 Mar 2017 23:23:05 +0000 (UTC)
To: ntpwg@lists.ntp.org
References: <CA564C5C-6CED-4810-BA2F-5433F2525249@isoc.org> <20170327133842.GK8192@localhost> <58D9FD22020000A1000255AD@gwsmtp1.uni-regensburg.de> <4cff4cd7-1eec-0e72-b235-1a8d65fc7fc4@nwtime.org> <58DA0F83020000A1000255CF@gwsmtp1.uni-regensburg.de> <CAJm83bCvuJTqoiP8SeYSwEceiJe90C+V8+3AfdgczJ-+L1sa9Q@mail.gmail.com>
From: Harlan Stenn <stenn@nwtime.org>
Message-ID: <33dc07d7-9c3b-a261-91f0-4c32b7f076a9@nwtime.org>
Date: Tue, 28 Mar 2017 16:23:06 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <CAJm83bCvuJTqoiP8SeYSwEceiJe90C+V8+3AfdgczJ-+L1sa9Q@mail.gmail.com>
X-DSPAM-Result: Innocent
X-DSPAM-Processed: Tue Mar 28 23:23:05 2017
X-DSPAM-Confidence: 0.9899
X-DSPAM-Improbability: 1 in 9809 chance of being spam
X-DSPAM-Probability: 0.0000
X-DSPAM-Signature: 6384,58daf059107502638626441
X-SA-Exim-Connect-IP: 66.220.13.234
X-SA-Exim-Rcpt-To: ntpwg@lists.ntp.org
X-SA-Exim-Mail-From: stenn@nwtime.org
X-SA-Exim-Version: 4.2
X-SA-Exim-Scanned: Yes (on mail1.ntp.org)
Subject: Re: [ntpwg] Antw: Re: Antw: Re: call for adoption (draft-dfranke-ntp-data-minimization)
X-BeenThere: ntpwg@lists.ntp.org
X-Mailman-Version: 2.1.20
Precedence: list
List-Id: IETF Working Group for Network Time Protocol <ntpwg.lists.ntp.org>
List-Unsubscribe: <http://lists.ntp.org/options/ntpwg>, <mailto:ntpwg-request@lists.ntp.org?subject=unsubscribe>
List-Archive: <http://lists.ntp.org/pipermail/ntpwg/>
List-Post: <mailto:ntpwg@lists.ntp.org>
List-Help: <mailto:ntpwg-request@lists.ntp.org?subject=help>
List-Subscribe: <http://lists.ntp.org/listinfo/ntpwg>, <mailto:ntpwg-request@lists.ntp.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org
Sender: ntpwg <ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org>
On 3/28/2017 7:08 AM, Daniel Franke wrote: > On 3/28/17, Ulrich Windl <Ulrich.Windl@rz.uni-regensburg.de> wrote: >> IMHO it would be consistent to set precision to 3 (the lowest possible >> precision (0.125s) where NTP will start to work) and use 29 bits of >> randomness then. Still a half billion attack packets might transit without >> being detected, but I doubt that. Ulrich, a precision of 3 is 8 seconds. > 2**29 packets is about 541 gigabits including ethernet headers, so on > a 1Gbps link is about a 0.18% chance of attacker success during the 1s > MAXDIST window. On a 10Gbps link this becomes 1.8%. That's a big > improvement over the status quo but still a non-negligible weakness. Daniel, you're continuing to focus on and assume that: - nobody will notice or care about these spoofs. The reference implementation from NTF/ntp.org reports these on both the client and the server side. - Once the client receives the response from the server, the origin timestamp is zeroed in the client so no more responses from the server will be accepted. This has all been said before, several times, and you continue to ignore these points. Please take a breath of fresh air. > What's the benefit of randomizing anything less than the full 64 bits? For extranet communications, I'd likely choose 64 bits. But I'd also consider this to be *my* policy choice. If somebody has good reason to pick a different number, they should be able to. I would generally not choose information hiding or extra randomizing on internal NTP traffic. -- Harlan Stenn <stenn@nwtime.org> http://networktimefoundation.org - be a member! _______________________________________________ ntpwg mailing list ntpwg@lists.ntp.org http://lists.ntp.org/listinfo/ntpwg
- [ntpwg] call for adoption (draft-dfranke-ntp-data… Karen O'Donoghue
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Paul Gear
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Miroslav Lichvar
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Miroslav Lichvar
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Salz, Rich via ntpwg
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Sharon Goldberg
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Miroslav Lichvar
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Aanchal Malhotra
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Miroslav Lichvar
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Harlan Stenn
- [ntpwg] Antw: Re: call for adoption (draft-dfrank… Ulrich Windl
- Re: [ntpwg] Antw: Re: call for adoption (draft-df… Harlan Stenn
- [ntpwg] Antw: Re: call for adoption (draft-dfrank… Ulrich Windl
- [ntpwg] Antw: Re: call for adoption (draft-dfrank… Ulrich Windl
- Re: [ntpwg] Antw: Re: call for adoption (draft-df… Hal Murray
- [ntpwg] Antw: Re: Antw: Re: call for adoption (dr… Ulrich Windl
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Harlan Stenn
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Daniel Franke
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Daniel Franke
- [ntpwg] Antw: Re: Antw: Re: Antw: Re: call for ad… Ulrich Windl
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Daniel Franke
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Salz, Rich via ntpwg
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Harlan Stenn
- Re: [ntpwg] Antw: Re: Antw: Re: call for adoption… Daniel Franke
- [ntpwg] Antw: Re: Antw: Re: Antw: Re: call for ad… Ulrich Windl
- [ntpwg] Antw: Re: Antw: Re: Antw: Re: call for ad… Ulrich Windl
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Miroslav Lichvar
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Greg Dowd
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… Daniel Franke
- Re: [ntpwg] call for adoption (draft-dfranke-ntp-… dieter.sibold
- [ntpwg] Antw: Re: call for adoption (draft-dfrank… Ulrich Windl
- [ntpwg] Antw: Re: call for adoption (draft-dfrank… Ulrich Windl
- Re: [ntpwg] Antw: Re: call for adoption (draft-df… Miroslav Lichvar