Re: [quicwg/base-drafts] handle reordered NEW_CONNECTION_ID frames (#3202)

Marten Seemann <> Fri, 08 November 2019 15:48 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 490E3120854 for <>; Fri, 8 Nov 2019 07:48:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -6.382
X-Spam-Status: No, score=-6.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 5GtvfQU0Zn49 for <>; Fri, 8 Nov 2019 07:48:23 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 50227120844 for <>; Fri, 8 Nov 2019 07:48:23 -0800 (PST)
Date: Fri, 08 Nov 2019 07:48:22 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=pf2014; t=1573228102; bh=5aytc4/MJlZ0dKqiF200oueq8jVaizqdZB3l+GEjAv8=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=ugQSWLSXcDyg7rlG/l1AKhKbTGh1WODGoM6/4mZTwowBSlJWQ27vHairPakDKNBqE pbQxXB9/Cp3twKQdUgFYREGQDs+faU3X+1L8/CnNifPItfdVloNLL5LNLfrIpJBcCA qf32PYl3wP8jasy6AAoLss0RNghxJIs4tiZ+zCQ0=
From: Marten Seemann <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/pull/3202/>
In-Reply-To: <quicwg/base-drafts/pull/>
References: <quicwg/base-drafts/pull/>
Subject: Re: [quicwg/base-drafts] handle reordered NEW_CONNECTION_ID frames (#3202)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5dc58e467d770_98d3fef8d2cd96029353"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: marten-seemann
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 08 Nov 2019 15:48:25 -0000

> Larger change, but one solution to that might be permitting a RCID frame to retire ranges instead of a single CID.

@MikeBishop I'm not sure if there's a problem here that we need to solve. The DoS that I described only works if an endpoint sends RETIRE_CONNECTION_ID frames for CIDs that it hasn't received / doesn't remember any more. As long as you only retire CIDs that you're actually keeping track of (as the spec currently says), the DoS doesn't work.

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: