From nobody Wed Mar 11 15:54:18 2020
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id B7C0D3A0914
 for <quic-issues@ietfa.amsl.com>; Wed, 11 Mar 2020 15:54:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.008
X-Spam-Level: 
X-Spam-Status: No, score=-2.008 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 HTML_IMAGE_ONLY_16=1.092, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1,
 SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=github.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id FYwOTm0O8AJp for <quic-issues@ietfa.amsl.com>;
 Wed, 11 Mar 2020 15:54:15 -0700 (PDT)
Received: from out-25.smtp.github.com (out-25.smtp.github.com [192.30.252.208])
 (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 9600B3A0912
 for <quic-issues@ietf.org>; Wed, 11 Mar 2020 15:54:15 -0700 (PDT)
Received: from github-lowworker-f144ac1.va3-iad.github.net
 (github-lowworker-f144ac1.va3-iad.github.net [10.48.16.59])
 by smtp.github.com (Postfix) with ESMTP id BBE7F281B7C
 for <quic-issues@ietf.org>; Wed, 11 Mar 2020 15:54:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
 s=pf2014; t=1583967254;
 bh=/V2hqYJLHkf5wsNTVwiZu7F2WPbtrr65UXhX6O+TkA8=;
 h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID:
 List-Archive:List-Post:List-Unsubscribe:From;
 b=quaT3I1MU+djOdyeNluKWkySyOBTfCHGO76wcEOfxMmzzrbsZJaspaOKX8/BRwCm9
 J1RI8HRxTdA/R12G4gGQvgyM/R1IOGWLS1O6PLnAoMEmen4Pb3HMd9zAXL9nPD2eIA
 OV7vJhy52sjm7GZr6Vq7MHHDm1xpOoAPgG4pKuM4=
Date: Wed, 11 Mar 2020 15:54:14 -0700
From: MikkelFJ <notifications@github.com>
Reply-To: quicwg/base-drafts
 <reply+AFTOJK5TEZMBGGRMRM3Y5LN4OVGRNEVBNHHCBQHUUM@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/3340/597919738@github.com>
In-Reply-To: <quicwg/base-drafts/issues/3340@github.com>
References: <quicwg/base-drafts/issues/3340@github.com>
Subject: Re: [quicwg/base-drafts] Anti-amplification limits should count junk
 too (#3340)
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_5e696c16ac387_37783fec92ccd968160294";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: mikkelfj
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/jbRxAE5TbcRCfhOlgwNyM2OTQsk>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG
 <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Mar 2020 22:54:17 -0000


----==_mimepart_5e696c16ac387_37783fec92ccd968160294
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

If random packets from a given source is counted, I could imagine a spoofed source attack that piggy backs on valid connections to amp up its own traffic.

Initial packets can have zero length SCID, and ODCID with very little information, so linking to CIDs might not be much more effective.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/3340#issuecomment-597919738
----==_mimepart_5e696c16ac387_37783fec92ccd968160294
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p></p>
<p>If random packets from a given source is counted, I could imagine a spoofed source attack that piggy backs on valid connections to amp up its own traffic.</p>
<p>Initial packets can have zero length SCID, and ODCID with very little information, so linking to CIDs might not be much more effective.</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/quicwg/base-drafts/issues/3340#issuecomment-597919738">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AFTOJK3N6RZI7YSBMFTBVHTRHAJBNANCNFSM4KGRWDLA">unsubscribe</a>.<img src="https://github.com/notifications/beacon/AFTOJK32PU4RG5IY2JSSBUDRHAJBNA5CNFSM4KGRWDLKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEORYP6Q.gif" height="1" width="1" alt="" /></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/quicwg/base-drafts/issues/3340#issuecomment-597919738",
"url": "https://github.com/quicwg/base-drafts/issues/3340#issuecomment-597919738",
"name": "View Issue"
},
"description": "View this Issue on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>
----==_mimepart_5e696c16ac387_37783fec92ccd968160294--

