Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id BA69312EA67
 for <quic-issues@ietfa.amsl.com>; Tue,  6 Jun 2017 23:46:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.799
X-Spam-Level: 
X-Spam-Status: No, score=-4.799 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001,
 RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001,
 URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=github.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id ZMJ_FqG27bqX for <quic-issues@ietfa.amsl.com>;
 Tue,  6 Jun 2017 23:46:56 -0700 (PDT)
Received: from o4.sgmail.github.com (o4.sgmail.github.com [192.254.112.99])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id EDA6212EA5A
 for <quic-issues@ietf.org>; Tue,  6 Jun 2017 23:46:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; 
 h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe;
 s=s20150108; bh=UBekGUpqODWJGGNRsM7B/kAOfb4=; b=kjYrK1aWxj9wAEeD
 iNhLCkj4oxejOZlLYjiCZnHhclI/N28l5gZgtZ2VjxWhyDtkMMSN0CiTJ/Us8zms
 d0JCo6AddzUndO48v/ldiukUbM+q6PgWVLW3A7Aj6OoJKQA4Ml+e0cqiyCLaooVZ
 zX08v+CwMpQN9Urhmri7pFFeC5c=
Received: by filter0814p1mdw1.sendgrid.net with SMTP id
 filter0814p1mdw1-31937-5937A15D-37
 2017-06-07 06:46:53.911465966 +0000 UTC
Received: from github-smtp2b-ext-cp1-prd.iad.github.net
 (github-smtp2b-ext-cp1-prd.iad.github.net [192.30.253.17])
 by ismtpd0006p1iad1.sendgrid.net (SG) with ESMTP id SinJhOH-Skyo77-nE0okbA
 for <quic-issues@ietf.org>; Wed, 07 Jun 2017 06:46:53.948 +0000 (UTC)
Date: Tue, 06 Jun 2017 23:46:53 -0700
From: MikkelFJ <notifications@github.com>
Reply-To: quicwg/base-drafts
 <reply+0166e4abc5631fce666d9c8a87b04e935c999cafc66f4b9192cf00000001154f635d92a169ce0df28989@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/597/306702712@github.com>
In-Reply-To: <quicwg/base-drafts/issues/597@github.com>
References: <quicwg/base-drafts/issues/597@github.com>
Subject: Re: [quicwg/base-drafts] Connection abort during handshake (#597)
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_5937a15dd5c32_7d533fb3671ffc3445759";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: mikkelfj
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak0B9yz16p8QT3knLdKRE1KFLF6FzufynN3V/u
 X+XRv5mMhK/I5CC462zhjOvM5VmaPjQ4mxEp2IDCobMnkASEdDZvtM2fz7RDXFSFCYzFwEDIgoZsrs
 qpa+LWWCcvQf4zqHE2gwn/YzDs24ds7cy/F+z/VdpPH5GgDEkYp6awynM7hX6cyBK1OmNxrMRm4W6R
 Q=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/MHWPsG9ICug07i3sJd8wg47yrHg>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG
 <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jun 2017 06:46:58 -0000

----==_mimepart_5937a15dd5c32_7d533fb3671ffc3445759
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

>Well thats why I think this is another reason for using Server Stateless Retry, which returns client's selected random packet number and can be validated by client. It would be hard for attacker to guess that value (2^31).

On using packet numbers for validation: I think it would be simpler to validate on a client and a server chosen nonce (aka Connection Id) because it requires less state, but I might be missing something. For example if failing on a second Client ClearText packet you need to remember all packet numbers and while retransmission does this, it is a different machinery. Having the nonces also simplifies state lookup.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/597#issuecomment-306702712
----==_mimepart_5937a15dd5c32_7d533fb3671ffc3445759
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<blockquote>
<p>Well thats why I think this is another reason for using Server Stateless=
 Retry, which returns client's selected random packet number and can be val=
idated by client. It would be hard for attacker to guess that value (2^31).=
</p>
</blockquote>
<p>On using packet numbers for validation: I think it would be simpler to v=
alidate on a client and a server chosen nonce (aka Connection Id) because i=
t requires less state, but I might be missing something. For example if fai=
ling on a second Client ClearText packet you need to remember all packet nu=
mbers and while retransmission does this, it is a different machinery. Havi=
ng the nonces also simplifies state lookup.</p>

<p style=3D"font-size:small;-webkit-text-size-adjust:none;color:#666;">&mda=
sh;<br />You are receiving this because you are subscribed to this thread.<=
br />Reply to this email directly, <a href=3D"https://github.com/quicwg/bas=
e-drafts/issues/597#issuecomment-306702712">view it on GitHub</a>, or <a hr=
ef=3D"https://github.com/notifications/unsubscribe-auth/AWbkq4fInxGheht_jgJ=
zTPPxUhc3wiNaks5sBkddgaJpZM4NxzZJ">mute the thread</a>.<img alt=3D"" height=
=3D"1" src=3D"https://github.com/notifications/beacon/AWbkqztKJgprwk6daLgmn=
BSIg5k6IQa4ks5sBkddgaJpZM4NxzZJ.gif" width=3D"1" /></p>
<div itemscope itemtype=3D"http://schema.org/EmailMessage">
<div itemprop=3D"action" itemscope itemtype=3D"http://schema.org/ViewAction=
">
  <link itemprop=3D"url" href=3D"https://github.com/quicwg/base-drafts/issu=
es/597#issuecomment-306702712"></link>
  <meta itemprop=3D"name" content=3D"View Issue"></meta>
</div>
<meta itemprop=3D"description" content=3D"View this Issue on GitHub"></meta>
</div>

<script type=3D"application/json" data-scope=3D"inboxmarkup">{"api_version"=
:"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"Gi=
tHub"},"entity":{"external_key":"github/quicwg/base-drafts","title":"quicwg=
/base-drafts","subtitle":"GitHub repository","main_image_url":"https://clou=
d.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290=
892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/asset=
s/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name=
":"Open in GitHub","url":"https://github.com/quicwg/base-drafts"}},"updates=
":{"snippets":[{"icon":"PERSON","message":"@mikkelfj in #597: \u003eWell th=
ats why I think this is another reason for using Server Stateless Retry, wh=
ich returns client's selected random packet number and can be validated by =
client. It would be hard for attacker to guess that value (2^31).\r\n\r\nOn=
 using packet numbers for validation: I think it would be simpler to valida=
te on a client and a server chosen nonce (aka Connection Id) because it req=
uires less state, but I might be missing something. For example if failing =
on a second Client ClearText packet you need to remember all packet numbers=
 and while retransmission does this, it is a different machinery. Having th=
e nonces also simplifies state lookup."}],"action":{"name":"View Issue","ur=
l":"https://github.com/quicwg/base-drafts/issues/597#issuecomment-306702712=
"}}}</script>=

----==_mimepart_5937a15dd5c32_7d533fb3671ffc3445759--

