Re: [quicwg/base-drafts] Version validation fields can't move or change (#498)

Victor Vasiliev <notifications@github.com> Mon, 31 July 2017 06:23 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C20DA126C0F for <quic-issues@ietfa.amsl.com>; Sun, 30 Jul 2017 23:23:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.798
X-Spam-Level:
X-Spam-Status: No, score=-9.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 27IhzzfhMzwe for <quic-issues@ietfa.amsl.com>; Sun, 30 Jul 2017 23:23:32 -0700 (PDT)
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2-ext2.iad.github.net [192.30.252.193]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3140C12F24E for <quic-issues@ietf.org>; Sun, 30 Jul 2017 23:23:32 -0700 (PDT)
Date: Sun, 30 Jul 2017 23:23:31 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501482211; bh=IG4/Ce/xjln13GZTY9dpLF0fRlz9C1vtZSghfI5tsFI=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=ppaYdUTrox0rRpHqTWICeBcfIQcsJNtVe/qbxHe6JfJATQipf8aoMTlNsoXJTQJDB M9TmsLolAt83PM/dS0SatFfXFFWA03jOrGQs+ln+h+13f0mU8D+XYilZqdnuPVkJQy E32ag3jmofjlbA2RMql46zvkqniVjn05ePrxXcK0=
From: Victor Vasiliev <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab14ef451c31ce5ecc62753e866048cf7ab80bbb7892cf0000000115968ee392a169ce0d7b2095@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/498/review/53134378@github.com>
In-Reply-To: <quicwg/base-drafts/pull/498@github.com>
References: <quicwg/base-drafts/pull/498@github.com>
Subject: Re: [quicwg/base-drafts] Version validation fields can't move or change (#498)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_597ecce365e69_25d83fe54cfb5c2c818c6"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: vasilvv
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/28Kvhi46L5WnrQQVO3SmWIGF-lM>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Jul 2017 06:23:34 -0000

vasilvv commented on this pull request.



> @@ -1131,6 +1131,13 @@ client MUST terminate with a QUIC_VERSION_NEGOTIATION_MISMATCH error code if
 version negotiation occurred but it would have selected a different version
 based on the value of the supported_versions list.
 
+The position and size of the version validation fields in the transport
+parameters MUST NOT change between different versions of QUIC.  If a version of
+QUIC needs to define a new format for transport parameters, it MUST define and
+use a new TLS extension rather than redefine the layout of the existing

I feel like it would be clearer if you expand on the attack you’re trying to mitigate.  Something like:
“When a peer accepts multiple versions of the handshake, it can potentially interpret the handshake as defined by any of the versions it supports.  Since the QUIC protocol relies on security of the handshake for authenticating the version, the position and the format of the version field in the handshake MUST be consistent across all QUIC versions supported by the client.”

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/498#discussion_r130279032