Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 4C10E12951A
 for <quic-issues@ietfa.amsl.com>; Thu,  2 Mar 2017 09:13:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.501
X-Spam-Level: 
X-Spam-Status: No, score=-6.501 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5,
 RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=github.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id en0QB9-aGNfg for <quic-issues@ietfa.amsl.com>;
 Thu,  2 Mar 2017 09:13:28 -0800 (PST)
Received: from github-smtp2b-ext-cp1-prd.iad.github.net
 (github-smtp2-ext2.iad.github.net [192.30.252.193])
 (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id E44D0129515
 for <quic-issues@ietf.org>; Thu,  2 Mar 2017 09:13:27 -0800 (PST)
Date: Thu, 02 Mar 2017 09:13:26 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
 s=pf2014; t=1488474807;
 bh=ilEI/+jPXglSvQjswOlD3iEyKcsRxeYYNSYnSdPw6Bk=;
 h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID:
 List-Archive:List-Post:List-Unsubscribe:From;
 b=KNn3fIv+QLGR73wvNd59mEWhlgFEUFi30NMjWcPkksoPtwz1OnIdL/EXJ7KQA/Zsn
 y30zdfkny+IwoyP+AmJLLRVP9cjD80KDBlkTZxJ++KC4m9RkV4sp3G+Lg3W1MoRQLh
 qmngX8s6Kc/IDKhxDNbH8mgNZBTbhxcdFOsBS+kk=
From: martinduke <notifications@github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/353/283716658@github.com>
In-Reply-To: <quicwg/base-drafts/issues/353@github.com>
References: <quicwg/base-drafts/issues/353@github.com>
Subject: Re: [quicwg/base-drafts] Replace CONNECTION_CLOSE with Public Reset
 (#353)
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_58b852b6f07f0_7e7f3faf02f6dc2c506c6";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinduke
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/m8Tg0kG6zL5ahLijVb8YnTPNjpY>
Cc: Subscribed <subscribed@noreply.github.com>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.17
Reply-To: quic@ietf.org
List-Id: Notification list for GitHub issues related to the QUIC WG
 <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Mar 2017 17:13:29 -0000


----==_mimepart_58b852b6f07f0_7e7f3faf02f6dc2c506c6
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

> we should be removing PUBLIC_RESET uses cases wherever possible because they have poor security properties.

I don't see what this achieves. We are not going to eliminate PUBLIC_RESET, so it will always be available for attackers who want to break connections. The protocol is only as strong as the PUBLIC_RESET authentication, so imposing additional security on a subset of termination messages achieves nothing.

This wouldn't be true if we declared different behavior on receipt of PUBLIC_RESET: for instance, the receiver could keep state for some amount of time, in case legitimate packets arrived after a spoofed reset. But in the absence of such a mechanism, CONNECTION_CLOSE achieves nothing.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/353#issuecomment-283716658
----==_mimepart_58b852b6f07f0_7e7f3faf02f6dc2c506c6
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<blockquote>
<p>we should be removing PUBLIC_RESET uses cases wherever possible becaus=
e they have poor security properties.</p>
</blockquote>
<p>I don't see what this achieves. We are not going to eliminate PUBLIC_R=
ESET, so it will always be available for attackers who want to break conn=
ections. The protocol is only as strong as the PUBLIC_RESET authenticatio=
n, so imposing additional security on a subset of termination messages ac=
hieves nothing.</p>
<p>This wouldn't be true if we declared different behavior on receipt of =
PUBLIC_RESET: for instance, the receiver could keep state for some amount=
 of time, in case legitimate packets arrived after a spoofed reset. But i=
n the absence of such a mechanism, CONNECTION_CLOSE achieves nothing.</p>=


<p style=3D"font-size:small;-webkit-text-size-adjust:none;color:#666;">&m=
dash;<br />You are receiving this because you are subscribed to this thre=
ad.<br />Reply to this email directly, <a href=3D"https://github.com/quic=
wg/base-drafts/issues/353#issuecomment-283716658">view it on GitHub</a>, =
or <a href=3D"https://github.com/notifications/unsubscribe-auth/AWbkq9x6F=
fTIm_qRCPDQU8oIJWCb4nFuks5rhvi2gaJpZM4MQZqy">mute the thread</a>.<img alt=
=3D"" height=3D"1" src=3D"https://github.com/notifications/beacon/AWbkqxL=
lCBW-i_eSlahIWAni4eVhsgekks5rhvi2gaJpZM4MQZqy.gif" width=3D"1" /></p>
<div itemscope itemtype=3D"http://schema.org/EmailMessage">
<div itemprop=3D"action" itemscope itemtype=3D"http://schema.org/ViewActi=
on">
  <link itemprop=3D"url" href=3D"https://github.com/quicwg/base-drafts/is=
sues/353#issuecomment-283716658"></link>
  <meta itemprop=3D"name" content=3D"View Issue"></meta>
</div>
<meta itemprop=3D"description" content=3D"View this Issue on GitHub"></me=
ta>
</div>

<script type=3D"application/json" data-scope=3D"inboxmarkup">{"api_versio=
n":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name"=
:"GitHub"},"entity":{"external_key":"github/quicwg/base-drafts","title":"=
quicwg/base-drafts","subtitle":"GitHub repository","main_image_url":"http=
s://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6=
-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubuserconte=
nt.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","=
action":{"name":"Open in GitHub","url":"https://github.com/quicwg/base-dr=
afts"}},"updates":{"snippets":[{"icon":"PERSON","message":"@martinduke in=
 #353: \u003e we should be removing PUBLIC_RESET uses cases wherever poss=
ible because they have poor security properties.\r\n\r\nI don't see what =
this achieves. We are not going to eliminate PUBLIC_RESET, so it will alw=
ays be available for attackers who want to break connections. The protoco=
l is only as strong as the PUBLIC_RESET authentication, so imposing addit=
ional security on a subset of termination messages achieves nothing.\r\n\=
r\nThis wouldn't be true if we declared different behavior on receipt of =
PUBLIC_RESET: for instance, the receiver could keep state for some amount=
 of time, in case legitimate packets arrived after a spoofed reset. But i=
n the absence of such a mechanism, CONNECTION_CLOSE achieves nothing."}],=
"action":{"name":"View Issue","url":"https://github.com/quicwg/base-draft=
s/issues/353#issuecomment-283716658"}}}</script>=

----==_mimepart_58b852b6f07f0_7e7f3faf02f6dc2c506c6--

