Re: [quicwg/base-drafts] CID's should be compared in constant time (#2477)

MikkelFJ <> Fri, 15 February 2019 19:53 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 43BDA130FAB for <>; Fri, 15 Feb 2019 11:53:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.597
X-Spam-Status: No, score=-1.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id og2kaj2ewR0c for <>; Fri, 15 Feb 2019 11:53:42 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 05820124D68 for <>; Fri, 15 Feb 2019 11:53:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed;; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=LsecRrX0gpU/MjdHQs/ZmzyOJ6E=; b=V2ils15rqmndEvZ7 aAAUHp204/lnMOVjM3LkG0yk9fIo76rvSpXGChUhJSynWr1TYd/kHvrgVWj/3yrK kFu/wVZNABfQ4LQ2PmshW9bGVpzFz4do0AOhwpi0ArVBuYtTQ9Q4ZAJ6thMj685v PCg8aVfLiDNAH8TBjEuzKKLLFXM=
Received: by with SMTP id filter0089p1iad2-17107-5C6718C4-B 2019-02-15 19:53:40.19654362 +0000 UTC m=+862041.099376365
Received: from (unknown []) by (SG) with ESMTP id O2VBC-phQmOQSZNptDeg1g for <>; Fri, 15 Feb 2019 19:53:40.239 +0000 (UTC)
Received: from (localhost []) by (Postfix) with ESMTP id 3F8363805C5 for <>; Fri, 15 Feb 2019 11:53:40 -0800 (PST)
Date: Fri, 15 Feb 2019 19:53:40 +0000
From: MikkelFJ <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/issues/2477/>
In-Reply-To: <quicwg/base-drafts/issues/>
References: <quicwg/base-drafts/issues/>
Subject: Re: [quicwg/base-drafts] CID's should be compared in constant time (#2477)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5c6718c43df11_4d663feac6cd45c422949d"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: mikkelfj
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak0JFkZdosE/jW0nlBDxAO/eVam1apkDo1tE+S w7Kyx5TRwRMtdbm18T0RTj817ZXVaYwUbVbNHnpvN4/wpVj+mRE/sfIan836JGS4A6a2HilXO1+2Xn JwpTQNyo3O4czfVco1pMI3UOaaO42EqAXcqe/VnLxLX7mom6Tgccvd/ghA==
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 15 Feb 2019 19:53:44 -0000

> However, if you have to be on path to observe processing time, this is moot.

You don't, because the endpoint cannot know what the correct path is before knowing the CID, assuming there is more than one possible path, as is usually the case.

BTW: there could be attacks on middle boxes that learn what valid CID's are, but do not compare these constant time. I'm not sure how effective that would be though.

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: