Re: [quicwg/base-drafts] Attacks Against Address Migration (#2582)

erickinnear <> Sat, 20 April 2019 00:45 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id C72E61201C8 for <>; Fri, 19 Apr 2019 17:45:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -8
X-Spam-Status: No, score=-8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id skFmnTNwnl7y for <>; Fri, 19 Apr 2019 17:45:03 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 8E98F1201BA for <>; Fri, 19 Apr 2019 17:45:03 -0700 (PDT)
Date: Fri, 19 Apr 2019 17:45:01 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=pf2014; t=1555721101; bh=6pnJiPJg4zfmcwmg0HgSnYmzsoa/0Ui4a2/R7amwemo=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=svJPRk0kq57cotM5z8cxVi+K3uBdER5dX4KXKtX/D6ChRmuUkAgivUoJpzldu5TsS 8FG2/EDIvzQKcFLXK+j0hreGE8bDMDz9vZbmWr3DddD6sugoirP8rXB+mH1SPcb17r 4CBzNJOky+e/EuN+y+aRmMQfZB/pZ+LukWUh99Wc=
From: erickinnear <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/issues/2582/>
In-Reply-To: <quicwg/base-drafts/issues/>
References: <quicwg/base-drafts/issues/>
Subject: Re: [quicwg/base-drafts] Attacks Against Address Migration (#2582)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5cba6b8de5289_511e3fa3cc2cd96813392f"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: erickinnear
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Sat, 20 Apr 2019 00:45:06 -0000

@MikeBishop Thanks for pulling up that text! I think you're correct in that we need to stop requiring remote address to match as well. 

That's essentially removal of this paragraph talking about what a successful validation is: 
- It was sent from the same remote address to which the corresponding
	  PATH_CHALLENGE was sent. If a PATH_RESPONSE frame is received from a different
	  remote address than the one to which the PATH_CHALLENGE was sent, path
	  validation is considered to have failed, even if the data matches that sent in

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: