Re: [quicwg/base-drafts] Allow Smaller Stateless Resets (#2927)

martinduke <notifications@github.com> Thu, 05 September 2019 15:17 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2AF761200F5 for <quic-issues@ietfa.amsl.com>; Thu, 5 Sep 2019 08:17:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.382
X-Spam-Level:
X-Spam-Status: No, score=-6.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BluKkaF3xRIH for <quic-issues@ietfa.amsl.com>; Thu, 5 Sep 2019 08:17:42 -0700 (PDT)
Received: from out-18.smtp.github.com (out-18.smtp.github.com [192.30.252.201]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB1AF1200F9 for <quic-issues@ietf.org>; Thu, 5 Sep 2019 08:17:42 -0700 (PDT)
Date: Thu, 05 Sep 2019 08:17:41 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1567696661; bh=xPS3uU7eYpRRyftov4ST5MAKc1rI0a5WvhJWBGaMs+o=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=kyZcjZPFEXUUDZPBIYY7scN1zcMZozr9Enhc0OcgDfRlNtEIJ8Y61MvcGPnmZLzF1 pVzZKMKX6C4H3QeAhmXAcJhq7PCZcGUd4Hi8Y3HzF/8RnQo8+yLgYyyivjDy8eeeVw D8cYYsU8kcQt0HBVc7eDIuO5itS6h0oFSD0KVDiI=
From: martinduke <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+AFTOJK6ZWV2P4JICUCW5B653PZT2LEVBNHHBYHMRI4@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/2927/c528419864@github.com>
In-Reply-To: <quicwg/base-drafts/pull/2927@github.com>
References: <quicwg/base-drafts/pull/2927@github.com>
Subject: Re: [quicwg/base-drafts] Allow Smaller Stateless Resets (#2927)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5d712715aabea_47793faecb8cd96c1166d0"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinduke
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/As9eaxksC5f__ax_8XEbxV55T8c>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Sep 2019 15:17:44 -0000

I find this text to be really unclear. Furthermore, if implementers don't pick up the SHOULD we're going to have detectable stateless resets all over the place.

And given the final version of extended connection IDs, we're talking about 2 additional bytes over the draft-20 status quo?

I don't find this change to be necessary, though I wouldn't raise a huge stink about it. However, I'd like to consider changing SHOULD to MUST. This seems like a potential security vulnerability.

At an absolute minimum, I'll propose an editorial rewrite to make these considerations clearer.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/2927#issuecomment-528419864