Re: [quicwg/base-drafts] introduce a version alias mechanism (#2573)

Nick Banks <> Fri, 12 April 2019 13:33 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 24E6A12064F for <>; Fri, 12 Apr 2019 06:33:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -3.001
X-Spam-Status: No, score=-3.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id vLyVbK9Wg9Ts for <>; Fri, 12 Apr 2019 06:33:45 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 33D681205CF for <>; Fri, 12 Apr 2019 06:33:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed;; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=fBjbefg6RmIs+EmbHbk4U/ciWo4=; b=J+YY16bIj4eoWclc 7XICzKzs30VQPqA0+zKoJUfOycoYIa6zBBBOrY29i4OOrri5mOroGCpjK9A3Yp1l WSs8JkH40r75zbnWxrzPdP/TaS7pZk4uqyGvRVJD6J5UYx34ac48BRAvh/R1Ha87 dISOxaRVMSP6xQNOQALRr0ZiVyk=
Received: by with SMTP id filter1044p1las1-31195-5CB093B5-F 2019-04-12 13:33:41.134962909 +0000 UTC m=+297572.834688108
Received: from (unknown []) by (SG) with ESMTP id USiyyquXRgWcdTaj-zX9eQ for <>; Fri, 12 Apr 2019 13:33:40.973 +0000 (UTC)
Received: from (localhost []) by (Postfix) with ESMTP id F37F21605B6 for <>; Fri, 12 Apr 2019 06:33:40 -0700 (PDT)
Date: Fri, 12 Apr 2019 13:33:41 +0000
From: Nick Banks <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/pull/2573/>
In-Reply-To: <quicwg/base-drafts/pull/>
References: <quicwg/base-drafts/pull/>
Subject: Re: [quicwg/base-drafts] introduce a version alias mechanism (#2573)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5cb093b4f2122_30a33ff9960d45c4127889"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: nibanks
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak3gho/KtPaZzg/SYh9k+U8Ze/gAzktN5KzzcO 46ypRPyBr/QEScfswZby8ACfLMLbZMURjnVa6SkXCtqTph7I2VwqfiLwATgR6uRs30oQ7ku07G1KBt kRPGd57hbb9HIL9JoaxtPy5OUiIujZyEIj0iUXBqjw+UH1I1DINrrmZQ01O1arUXmMx+QmutVn7Ra7 0=
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 12 Apr 2019 13:33:47 -0000

I do fear that this feature will make a generic, independent DDoS solution practically impossible. The more I talk to folks on the DDoS side, the more push back I get from **any** type of coordination between backend servers and the DDoS device. If there is no coordination, then the device will not understand these aliased version numbers; and therefore will not be able to reply with a version specific response (Retry).

The **only** course of action the device will have is to send back a VN packet with a reserved field, and drop the incoming packets for new connections. This is definitely not ideal, as I have no idea how clients would use this for back off logic. I'd assume they'd immediately fallback to H2, but when would they try QUIC again?

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: