Re: [quicwg/base-drafts] Saving a round-trip time in the initial handshakes with retry (#2552)

Erik Sy <notifications@github.com> Mon, 01 April 2019 12:00 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6DD6B12010E for <quic-issues@ietfa.amsl.com>; Mon, 1 Apr 2019 05:00:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.001
X-Spam-Level:
X-Spam-Status: No, score=-8.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j3MxdYyxejAi for <quic-issues@ietfa.amsl.com>; Mon, 1 Apr 2019 05:00:34 -0700 (PDT)
Received: from out-3.smtp.github.com (out-3.smtp.github.com [192.30.252.194]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1977812010C for <quic-issues@ietf.org>; Mon, 1 Apr 2019 05:00:34 -0700 (PDT)
Date: Mon, 01 Apr 2019 05:00:32 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1554120032; bh=19bmvdPeoi+IghCaf7q0QeD3mP+St+lRIlXiwsRwgvE=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=ocYzaGMvF+xw5Z/zkI9SpMAooc9HwK2vs0WSWK9GwL40wGUYWElEK6/rDjjuAAE0g +pLB1PjuZt88SSMkJTu/Vf5bgLcQwHKvgZS1VQ3hVgAvgC/DYVII5JuBMP6ICGRKfl YJCssRsrK/NBsLAEHEhluleupsz5Ez3DYNn+Ixus=
From: Erik Sy <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4abb98464b99b1fcaf75ebb8ae0b84fe978a395b84892cf0000000118b9bf6092a169ce195632b6@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/2552/478550385@github.com>
In-Reply-To: <quicwg/base-drafts/issues/2552@github.com>
References: <quicwg/base-drafts/issues/2552@github.com>
Subject: Re: [quicwg/base-drafts] Saving a round-trip time in the initial handshakes with retry (#2552)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5ca1fd609f638_35cb3f87c78d45bc954fc"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: kirsey
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/Gk0cSnJuMPfAYpwQQ0080C1dNbY>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Apr 2019 12:00:37 -0000

A QUIC server that is not validating the source address of a client before proceeding with the connection establishment is a vulnerable system. Adversaries can easily launch attacks to exhaust the server's resources or exploit the server within reflection attacks against other endpoints. 
QUIC deploys mitigations such as limiting the response size. However, it is unclear at this point in time whether these defenses are sufficient.
As the Internet is a hostile place, we will observe that QUIC servers have to make use of stateless retries to validate the client’s source address. However, a trustworthy prediction of the number of connection establishments using a stateless retry seems currently not to be feasible.

The proposal allows compensating for the costs of preventing IP address spoofing across connections to several hostnames. Thus, it provides an improved security versus performance tradeoff compared to the status quo.

As the probability of a stateless retry seems to be higher for resumed TLS sessions, session resumption across SNI values provides another incentive to implement this proposal.

If we agree, that this presents a useful feature for QUIC’s connection establishment, then I prefer to mark it quicv1. The reason is, that it allows saving round-trip during the establishment of initial connections even when the same security requirements are applied as TLS over TCP does. Thus, it provides an additional incentive to deploy QUIC instead of using TLS over TCP.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/2552#issuecomment-478550385