Re: [quicwg/base-drafts] Threat model discussion does not cover handshake MITM (#3512)

Lucas Pardue <> Sat, 18 April 2020 12:57 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id A0DDC3A08AA for <>; Sat, 18 Apr 2020 05:57:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.721
X-Spam-Status: No, score=-1.721 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.168, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id JR77XpAofmvS for <>; Sat, 18 Apr 2020 05:57:05 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id DBD023A08AD for <>; Sat, 18 Apr 2020 05:56:59 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id C1162282A7A for <>; Sat, 18 Apr 2020 05:56:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=pf2014; t=1587214618; bh=evO/aOQBHGK4Svdf6oY4b618l1+r8Civ6W9TCGoMHVk=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=TuLZs6cWRcHZ163Z7+7JgbmAdPh+jJbM64n8UcSdXY4BtoJtTrsNEfdmxdf9LCEyK iGzafwDt1q8JBMF03XmCdTcJKO+DNjHUASRfGAD7hCrFGd8oSukqnYuJqwYltRvYtF nEB+0OZMH0fROlrGQQx80P+lfqP+z8DRspms/kOU=
Date: Sat, 18 Apr 2020 05:56:58 -0700
From: Lucas Pardue <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/issues/3512/>
In-Reply-To: <quicwg/base-drafts/issues/>
References: <quicwg/base-drafts/issues/>
Subject: Re: [quicwg/base-drafts] Threat model discussion does not cover handshake MITM (#3512)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5e9af91ab093e_4d3e3fe3ac6cd96c39438c"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: LPardue
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Sat, 18 Apr 2020 12:57:08 -0000

The options for triage are close it, mark as editorial, or mark as design. 

This has a needs-discussion, and I'm seeing a lack of any discussion. So you might see where my thought process is going...

@erickinnear this relates to your PR on the QUIC threat model. Are you willing to provide some comment that helps us triage the issue?

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: