Re: [quicwg/base-drafts] Version validation fields can't move or change (#498)

Mike Bishop <notifications@github.com> Mon, 31 July 2017 21:08 UTC

Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46F94131CDC for <quic-issues@ietfa.amsl.com>; Mon, 31 Jul 2017 14:08:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level:
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jBu0eeEhqgFy for <quic-issues@ietfa.amsl.com>; Mon, 31 Jul 2017 14:08:01 -0700 (PDT)
Received: from o10.sgmail.github.com (o10.sgmail.github.com [167.89.101.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BAA32129B35 for <quic-issues@ietf.org>; Mon, 31 Jul 2017 14:08:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=mJCFp4u+Y3uphKuPc8RHJUc4X6M=; b=NLsDx/tTwHKzWtM0 jZBDFty/vR5vlKFHj46ZpAfDPcQpx+5tEJ3sFVU7S9+R24PjWF5HtLALE1oacGGK jUQwzaOlWoVCrGXCMvjx+3jfV13SYEXN9OAgF4pD3vgRknrRLJqCBeMnZbI/9MM0 tfpRj/We7h+SsnsgRiv2qdl7bik=
Received: by filter0483p1mdw1.sendgrid.net with SMTP id filter0483p1mdw1-27264-597F9C30-46 2017-07-31 21:08:00.69015728 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0002p1iad1.sendgrid.net (SG) with ESMTP id 0DgwY1BmR7OZTyE_MCanxw for <quic-issues@ietf.org>; Mon, 31 Jul 2017 21:08:00.712 +0000 (UTC)
Date: Mon, 31 Jul 2017 21:08:00 +0000
From: Mike Bishop <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab459244f3c5e1a78211b4e6dc3821e27207edaf6a92cf0000000115975e3092a169ce0d7b2095@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/498/c319196942@github.com>
In-Reply-To: <quicwg/base-drafts/pull/498@github.com>
References: <quicwg/base-drafts/pull/498@github.com>
Subject: Re: [quicwg/base-drafts] Version validation fields can't move or change (#498)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_597f9c309110c_4af73fb80074bc2c1171c1"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: MikeBishop
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak1S/1sTO1I0V2or4cZHir9VFpSUiHsx9UGk+q Ccj01rsXnG1vvwApaaIa9Tvj+4Bt9gQppBdi3q/4v9YNg1XefPPBJRTUGGPYRAVfgSRaLiy0IuqY88 X2RVbW+FstczexapfHOZ/bx4rAT7xMhd/IMOaUdMcXzdQOg7qCKdqyCqbItbL/xyf7x/zRQIholb1+ A=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/WPvrgyzs2EN7asi7D-iCt6_awOE>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Jul 2017 21:08:03 -0000

It took me a couple times through the issue and the PR to figure out the actual attack here, and I don't think the current text actually captures it.  What finally clicked for me was that, although the version number is explicitly given in the packet, an on-path attacker who tried to force a version negotiation mismatch could also undetectably modify the contents of the version field in the packet header.  (Because the integrity protection / encryption on the packets at this point is trivially recalculated by an attacker.)  It's the contents of the handshake that can't be modified without detection, but we have to guard against getting just the right set of transport parameters in the future that looks like the version confirmation one would expect from the current version.

So what we're actually saying is that, if the version validation fields are in a different location in a different version of QUIC, they MUST be unmistakably different from a valid confirmation of having selected the current version or any future version that uses this handshake and transport settings format.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/498#issuecomment-319196942