[quicwg/base-drafts] Add initial threat model appendix (#2925)

Eric Kinnear <notifications@github.com> Tue, 23 July 2019 05:00 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1C7212007C for <quic-issues@ietfa.amsl.com>; Mon, 22 Jul 2019 22:00:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8
X-Spam-Level:
X-Spam-Status: No, score=-8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lyyBSPK4iLzT for <quic-issues@ietfa.amsl.com>; Mon, 22 Jul 2019 22:00:09 -0700 (PDT)
Received: from out-5.smtp.github.com (out-5.smtp.github.com [192.30.252.196]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E9B53120033 for <quic-issues@ietf.org>; Mon, 22 Jul 2019 22:00:08 -0700 (PDT)
Date: Mon, 22 Jul 2019 22:00:08 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1563858008; bh=M7w6OGX64V4hNqZK8fuCYTtJ0gGtZFlndASENHVj4sI=; h=Date:From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post: List-Unsubscribe:From; b=j3wfLpqtvz8nN0WKX7fl55GZItJXGFhpFGS3lR0vuyJtRIyZhu5i+CMM1R8+pdN+g e5jl7/f0a8I4ay9EGV7bwvtx+6cGkMpScLiWfubT4pfWEgvGg37iO3+K8Fhfs3tLlr IOocog0aV8eXEaW25wUrI4KT3KkFid3+aC6ekXIA=
From: Eric Kinnear <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+AFTOJK56XEYSZYHGFS7SYBN3IPDNREVBNHHBYGSUE4@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/2925@github.com>
Subject: [quicwg/base-drafts] Add initial threat model appendix (#2925)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5d36945896c4_1f5b3fa4bd2cd96c55075"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: erickinnear
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/FvtLNdFQ1nxI7LOocZmPuJL26uk>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Jul 2019 05:00:11 -0000

This adds an appendix for a QUIC threat model, filling in only the migration section (for #2143, some of the rest of the threat model will come in #2387).

Some wordsmithing can be applied here, and we may want additional issues to fill out detailed descriptions of some of the worst attacks and outline heuristics that might help, but for now I'm focusing this purely on documenting what's possible/not possible for an attacker to do today.
You can view, comment on, or merge this pull request online at:

  https://github.com/quicwg/base-drafts/pull/2925

-- Commit Summary --

  * Initial threat model appendix

-- File Changes --

    M draft-ietf-quic-transport.md (171)

-- Patch Links --

https://github.com/quicwg/base-drafts/pull/2925.patch
https://github.com/quicwg/base-drafts/pull/2925.diff

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/2925