Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 01E67130E78
 for <quic-issues@ietfa.amsl.com>; Sun, 23 Dec 2018 20:06:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.661
X-Spam-Level: 
X-Spam-Status: No, score=-6.661 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.065, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404,
 HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5,
 SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=github.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id L-KAM_cYWgtI for <quic-issues@ietfa.amsl.com>;
 Sun, 23 Dec 2018 20:06:28 -0800 (PST)
Received: from out-1.smtp.github.com (out-1.smtp.github.com [192.30.252.192])
 (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 5B55D130E79
 for <quic-issues@ietf.org>; Sun, 23 Dec 2018 20:06:28 -0800 (PST)
Date: Sun, 23 Dec 2018 20:06:27 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
 s=pf2014; t=1545624387;
 bh=2f1+flbVXyUzR7x7WWCCT9XqT8qlhJHLMl45DJUbNL8=;
 h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID:
 List-Archive:List-Post:List-Unsubscribe:From;
 b=IHekHyNHyx7mPRdYTJz97gPU1m2mYBNzdPsHRFx6H1VF7RIZVZy0ApbiS2RgaiLRJ
 dkc/9UQC5VPow07Bz6wLC5fIABmJZfu8w+z9YOSA4FwP73kWpzdSTQT7Y9aTgnXybx
 +XxgjS5b4gMZMlAePAWSxdJdhCAz3Vt9tYKL0fzQ=
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts
 <reply+0166e4abd570635745366f209381ccb7074ddac95af2eab292cf0000000118381d4392a169ce17719422@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/2241/c449683536@github.com>
In-Reply-To: <quicwg/base-drafts/pull/2241@github.com>
References: <quicwg/base-drafts/pull/2241@github.com>
Subject: Re: [quicwg/base-drafts] Remove PATH_RESPONSE limits (#2241)
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_5c205b437e47a_52433f9b81ad45c4116151b";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/Lk9VhIoM8vN0bUid_WaXBQdwd88>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG
 <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Dec 2018 04:06:30 -0000


----==_mimepart_5c205b437e47a_52433f9b81ad45c4116151b
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

The counter measure we have against amplification is the initial congestion window.  We won't send more than that.  That's higher than the x3 we have during the handshake, but I think that's a reasonable balance, considering that the attacker in this context has to spend a considerable amount of effort.

Yes, this is a policy question, but I'm happy with it.  (Though we should probably highlight this when asking for review.)

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/2241#issuecomment-449683536
----==_mimepart_5c205b437e47a_52433f9b81ad45c4116151b
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p>The counter measure we have against amplification is the initial conge=
stion window.  We won't send more than that.  That's higher than the x3 w=
e have during the handshake, but I think that's a reasonable balance, con=
sidering that the attacker in this context has to spend a considerable am=
ount of effort.</p>
<p>Yes, this is a policy question, but I'm happy with it.  (Though we sho=
uld probably highlight this when asking for review.)</p>

<p style=3D"font-size:small;-webkit-text-size-adjust:none;color:#666;">&m=
dash;<br />You are receiving this because you are subscribed to this thre=
ad.<br />Reply to this email directly, <a href=3D"https://github.com/quic=
wg/base-drafts/pull/2241#issuecomment-449683536">view it on GitHub</a>, o=
r <a href=3D"https://github.com/notifications/unsubscribe-auth/AWbkq1CrPI=
YXmdktAig0LmGO5ZYJg7TAks5u8FLDgaJpZM4ZdYU2">mute the thread</a>.<img src=3D=
"https://github.com/notifications/beacon/AWbkq2PBNSoj0-yklsd14VhFvi9hdrDd=
ks5u8FLDgaJpZM4ZdYU2.gif" height=3D"1" width=3D"1" alt=3D"" /></p>
<script type=3D"application/json" data-scope=3D"inboxmarkup">{"api_versio=
n":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name"=
:"GitHub"},"entity":{"external_key":"github/quicwg/base-drafts","title":"=
quicwg/base-drafts","subtitle":"GitHub repository","main_image_url":"http=
s://github.githubassets.com/images/email/message_cards/header.png","avata=
r_image_url":"https://github.githubassets.com/images/email/message_cards/=
avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/q=
uicwg/base-drafts"}},"updates":{"snippets":[{"icon":"PERSON","message":"@=
martinthomson in #2241: The counter measure we have against amplification=
 is the initial congestion window.  We won't send more than that.  That's=
 higher than the x3 we have during the handshake, but I think that's a re=
asonable balance, considering that the attacker in this context has to sp=
end a considerable amount of effort.\r\n\r\nYes, this is a policy questio=
n, but I'm happy with it.  (Though we should probably highlight this when=
 asking for review.)"}],"action":{"name":"View Pull Request","url":"https=
://github.com/quicwg/base-drafts/pull/2241#issuecomment-449683536"}}}</sc=
ript>
<script type=3D"application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/quicwg/base-drafts/pull/2241#issuecomment-4=
49683536",
"url": "https://github.com/quicwg/base-drafts/pull/2241#issuecomment-4496=
83536",
"name": "View Pull Request"
},
"description": "View this Pull Request on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>=

----==_mimepart_5c205b437e47a_52433f9b81ad45c4116151b--

