Re: [pntaw] More on draft-hutton-rtcweb-nat-firewall-considerations

Melinda Shore <> Wed, 25 September 2013 17:27 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 8581E21F9950 for <>; Wed, 25 Sep 2013 10:27:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.443
X-Spam-Status: No, score=-2.443 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, SUBJECT_FUZZY_TION=0.156]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id e-dob2M1sJbH for <>; Wed, 25 Sep 2013 10:27:15 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:400e:c03::22b]) by (Postfix) with ESMTP id 1692711E80F3 for <>; Wed, 25 Sep 2013 10:27:15 -0700 (PDT)
Received: by with SMTP id hz1so128670pad.30 for <>; Wed, 25 Sep 2013 10:27:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=A/+AgF1VAHMluA8P1gWt1wo+6lcHwQA2DGOJvf5VA90=; b=zNfFeCf8HofGI/A9kMQa0NhD1KsWpS2S1i+r7I1essXBZ2WkoiBN7ynOpxzCFzOsP8 +P5uC6+OgWAilOcnUYqfnJ4nf/BFMLox5akp9KZJZIuXnE6qJJlphyf9IhqmCP4RL0k+ VHGSfIPGx7wR1q8RzAaVv2I0W51JHvSPN9qCWKRSkhnR5xI/lIv3Y0qXqN4/onQvvDwR 6Ie3+XbiwNBXIZJGXHI7HUA7BpFjyJplDJZOq+fc09ETzlodcuuFmp+l/bo2t0bUCGnv i5m+YU+6RJgtaWT1EC+3VQAVRBzUnJCQEELO4EFO989nkYoD10N1/X9xe3/wnKswigh+ rQTA==
X-Received: by with SMTP id pw7mr34229106pbb.106.1380130034751; Wed, 25 Sep 2013 10:27:14 -0700 (PDT)
Received: from spandex.local ( []) by with ESMTPSA id k4sm48981667pbd.11.1969. (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 25 Sep 2013 10:27:13 -0700 (PDT)
Message-ID: <>
Date: Wed, 25 Sep 2013 09:27:11 -0800
From: Melinda Shore <>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
References: <> <> <> <> <>
In-Reply-To: <>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: Re: [pntaw] More on draft-hutton-rtcweb-nat-firewall-considerations
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion list for practices related to proxies, NATs, TURN, and WebRTC" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 25 Sep 2013 17:27:15 -0000

On 9/25/13 4:14 AM, Harald Alvestrand wrote:
> I'm not sure authentication helps here - once you've sent off a request
> to the evil server, you've opened the hole. It would even be good for
> the evil server to give a correct answer, since that increases the
> chances that the hole would remain open - you'll be using it.

Authentication doesn't help - there needs to be some trusted
party to the transaction who can vouch for the legitimacy of
the request.  It's a lot easier with VoIP, as you've generally
got some sort of call control server mediating the transaction
and that terminates (and reoriginates) signaling requests,
so they know what's going on.

> But - all those packets will end up at the WebRTC client. And that had
> *better* be hardened against outsiders anyway, because that hole *is*
> going to be open.

That's a broader firewall issue, I think, regardless of
whether or not <whatever> is being used to open firewall
pinholes.  But basically I see two issues here:

1) that an attacker can subvert the technology to
open firewall pinholes, and
2) undermining the ability of the firewall to enforce local
policy by giving users the ability to punch holes in
contravention of that policy

>From an operational standpoint the second is the more serious
issue, I think.  Most of the arguments I've heard against that
being an issue have been ideological in nature.  That's not
necessarily a bad thing and I actually agree that firewalls
are harmful to network architecture, that they're largely
responsible for crunchy-on-the-outside-soft-on-the-inside
mindsets on the parts of network and security admins (and
corporate auditors), etc., but I think in the real world we
need to acknowledge that they're out there and are perceived
has having value by the people who deploy them, and giving
users the ability to scoot around firewall policy is