Re: [quicwg/base-drafts] Clarify Actions on nonzero Reserved Bits (#2280)

David Schinazi <notifications@github.com> Wed, 09 January 2019 21:08 UTC

Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE162130FD4 for <quic-issues@ietfa.amsl.com>; Wed, 9 Jan 2019 13:08:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.149
X-Spam-Level:
X-Spam-Status: No, score=-6.149 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-4.553, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6ggsMZ_lmG_L for <quic-issues@ietfa.amsl.com>; Wed, 9 Jan 2019 13:08:32 -0800 (PST)
Received: from o10.sgmail.github.com (o10.sgmail.github.com [167.89.101.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D16D6130EAB for <quic-issues@ietf.org>; Wed, 9 Jan 2019 13:08:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=7AEmce7in4lU2PjcgnUGmH+/jhc=; b=lfbx+hc+TMuvsElw za+StBTM4CPuEFSGhUzrPbvIOEacs69O5pTZ7smDVWZ8zXhzGpIA5uA3G0NOQYRN CkvRKCpKSUyqHGqLbE3r/RhMK/YB3VSJWNCR9fA7JefaA5qYsgyb5ZdX+0O/Xdtf a+MAYVa15Uwuj4RwhRebv+mi2H8=
Received: by filter1612p1mdw1.sendgrid.net with SMTP id filter1612p1mdw1-6374-5C3662CD-26 2019-01-09 21:08:29.835160038 +0000 UTC m=+156358.116043478
Received: from github-lowworker-dcc078e.cp1-iad.github.net (unknown [192.30.252.44]) by ismtpd0045p1iad1.sendgrid.net (SG) with ESMTP id l_lMLx9-R4eGxuSidAOJ5A for <quic-issues@ietf.org>; Wed, 09 Jan 2019 21:08:29.830 +0000 (UTC)
Received: from github.com (localhost [127.0.0.1]) by github-lowworker-dcc078e.cp1-iad.github.net (Postfix) with ESMTP id C8EC82C039C for <quic-issues@ietf.org>; Wed, 9 Jan 2019 13:08:29 -0800 (PST)
Date: Wed, 09 Jan 2019 21:08:29 +0000
From: David Schinazi <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab4297d959d0ea2534c0b199d752db7155eaa0230592cf00000001184e24cd92a169ce178a377a@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/2280/c452835167@github.com>
In-Reply-To: <quicwg/base-drafts/pull/2280@github.com>
References: <quicwg/base-drafts/pull/2280@github.com>
Subject: Re: [quicwg/base-drafts] Clarify Actions on nonzero Reserved Bits (#2280)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5c3662cdc198c_28703f9861ed45c0129759"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: DavidSchinazi
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak2YYwHl5vrAIvnmQzQy6MyHkrkobz9jHP52fD qP/PyzN0MkO1BQtccDVCV7MI0rx+tXRmHpn4gCOrYz1VUNxTzNKRkKzMvtiFGz4KxZPtxzzqJUiaai JTqOcy3hnk1M7JfB1QvwTUDbfE7bh/nAQkKBEO02ZOycuy3Z1hTioLeZXM1ese8QJuI89jEM/Nw8kB U=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/g8F8VCm7o0MD792FTCy6a0dgM2M>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jan 2019 21:08:34 -0000

Out of curiosity, why are we validating these bits in the first place? Can't we just say receivers MUST ignore them? That removes timing attacks and also allows for future extensibility. I get that these are not inside the full encryption boundary but the associated data + header protection boundary should be good enough to prevent middleboxes from looking at or messing with these bits.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/2280#issuecomment-452835167