Re: [quicwg/base-drafts] Can Finished be sent as 1-RTT data? (#785)

Martin Thomson <notifications@github.com> Mon, 25 September 2017 23:47 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 434EF134607 for <quic-issues@ietfa.amsl.com>; Mon, 25 Sep 2017 16:47:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.896
X-Spam-Level:
X-Spam-Status: No, score=-7.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s9O1WsUQHJGA for <quic-issues@ietfa.amsl.com>; Mon, 25 Sep 2017 16:47:04 -0700 (PDT)
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2-ext2.iad.github.net [192.30.252.193]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 02A34134606 for <quic-issues@ietf.org>; Mon, 25 Sep 2017 16:47:03 -0700 (PDT)
Date: Mon, 25 Sep 2017 16:47:03 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1506383223; bh=CzF4//ESCaScG07UyQMBSErNUUO4wXk5XdvZL/fQX88=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=GJS2B3af2dRuP3S2ByPb3x7SS25OxsTRINagIENogf03WIcVVgk/xOo1F75ZfKPHM mO86vMxseuoSYkjmXOjRFyDR/g+bsujEHwxCi0X4KRKrnYIfGQsz8HBF9XZBOCpokx qOqRUoADBXB+xQh1MWgBS1A2kbjQpHcUB/PGuL8g=
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab2ef426f5b49e0b00251a5c9eabd190d386a98eb192cf0000000115e1577792a169ce0f7388f0@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/785/332045196@github.com>
In-Reply-To: <quicwg/base-drafts/issues/785@github.com>
References: <quicwg/base-drafts/issues/785@github.com>
Subject: Re: [quicwg/base-drafts] Can Finished be sent as 1-RTT data? (#785)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_59c9957753a29_65593fd2b5d64f80596ae"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/DrxOzYaTauZr2g6OjfxBKF3ZkzM>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Sep 2017 23:47:05 -0000

@igorlord, I think that @huitema is more concerned about the time between when the server sends its Finished and when it receives the client Finished.  At this time, the server and client share keys and could authenticate all packets, but the connection is still vulnerable to denial of service until the server receives the client Finished.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/785#issuecomment-332045196