[quicwg/base-drafts] Equivalence of preferred_address and NEW_CONNECTION_ID (#3560)
Martin Thomson <notifications@github.com> Tue, 31 March 2020 00:14 UTC
We don't prohibit the use of a zero-length connection ID in the preferred_address transport parameter. So a server can use a connection ID during connection establishment, then remove privacy protections by moving to a unique address (see #3559). Of course, this is largely moot, as the privacy protection offered through the use of connection IDs toward a unique address is nil. In either case, we should clarify whether preferred_address is exactly like NEW_CONNECTION_ID, or whether it has its own rules. Right now, it looks like it has its own rules and that is likely bad. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/issues/3560
