Re: [quicwg/base-drafts] Add protection against abusive packer number sequences (#1752)

Martin Thomson <notifications@github.com> Mon, 24 September 2018 22:25 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BCC7131154 for <quic-issues@ietfa.amsl.com>; Mon, 24 Sep 2018 15:25:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.01
X-Spam-Level:
X-Spam-Status: No, score=-8.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_DKIMWL_WL_HIGH=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C9lVCFp9dCfQ for <quic-issues@ietfa.amsl.com>; Mon, 24 Sep 2018 15:25:13 -0700 (PDT)
Received: from out-6.smtp.github.com (out-6.smtp.github.com [192.30.252.197]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C143130E60 for <quic-issues@ietf.org>; Mon, 24 Sep 2018 15:25:13 -0700 (PDT)
Date: Mon, 24 Sep 2018 15:25:12 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1537827912; bh=WmlT7ripaCbJpUdZKQcQeARx00zLUhSAydd7VYV57H4=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=QiOVga2d7C9fl6SZfWsFV8Hazj6sRExxzkUHN8UDtDZUVtfTv1s2UmjPGbjilYKXA 98JYwxZF8f19Fhm/RtEQZu6v2uhpRKXbnBvvIXGHC2wibI2pS73HSGvSn2jD7+Emxx QtoJWBsuS4p32BS9iIbb+CpQ0/e2oNm4icTrlRK0=
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab8a3f65cab196e86f47112e03b84f6184cc279da092cf0000000117c1264892a169ce157e9fb2@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/1752/c424145727@github.com>
In-Reply-To: <quicwg/base-drafts/pull/1752@github.com>
References: <quicwg/base-drafts/pull/1752@github.com>
Subject: Re: [quicwg/base-drafts] Add protection against abusive packer number sequences (#1752)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5ba964489b16d_31ae3fd5ee0d45b8844a"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/Syjhs4xVl3YgMl2kE-pYUHquGME>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Sep 2018 22:25:16 -0000

Closing based on discussion.  We concluded that while there are optimizations that might be exposed to some sort of manipulation, the most obvious implementation isn't vulnerable.  Anyone optimizing can probably work this out for themselves.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/1752#issuecomment-424145727