From nobody Thu Sep 10 00:16:49 2020
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 606123A0F9E
 for <quic-issues@ietfa.amsl.com>; Thu, 10 Sep 2020 00:16:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.099
X-Spam-Level: 
X-Spam-Status: No, score=-3.099 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1,
 RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001,
 URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=github.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id X6ofudesFgBk for <quic-issues@ietfa.amsl.com>;
 Thu, 10 Sep 2020 00:16:47 -0700 (PDT)
Received: from out-18.smtp.github.com (out-18.smtp.github.com [192.30.252.201])
 (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 0F7F23A0F96
 for <quic-issues@ietf.org>; Thu, 10 Sep 2020 00:16:47 -0700 (PDT)
Received: from github-lowworker-9bcb4a1.ac4-iad.github.net
 (github-lowworker-9bcb4a1.ac4-iad.github.net [10.52.25.84])
 by smtp.github.com (Postfix) with ESMTP id 26308340E4B
 for <quic-issues@ietf.org>; Thu, 10 Sep 2020 00:16:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
 s=pf2014; t=1599722201;
 bh=OqCIZV5pJTmqDsnRU+3PjruN1Czrw8oLVNx+EuJxUb4=;
 h=Date:From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post:
 List-Unsubscribe:From;
 b=xYd1US4I6tkSIi1kWFlWgIHpwU1RuHITKtF25BR6lSdmL4zKAZYl/q/kCc4fW/Ljk
 Efq17YvpTui7ifkeO/tMO2FfeD/nlvLVCkdxm8RCaGouveKsBxIHIhbTxj698jUim/
 4THIkGAYvwe1OtaQ2ZLTwUDq+h3fcOOoc5MkYt7E=
Date: Thu, 10 Sep 2020 00:16:41 -0700
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts
 <reply+AFTOJK5HUAKTPHZKUQADIEF5MWZ5TEVBNHHCTE4YVI@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/4089@github.com>
Subject: [quicwg/base-drafts] Remove recommendation to not include tokens
 (#4089)
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_5f59d2d915e6a_51c719f0515545";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/pH7EpaJ0qfTI3yTCpPMExvh7DUg>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG
 <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>,
 <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Sep 2020 07:16:48 -0000


----==_mimepart_5f59d2d915e6a_51c719f0515545
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

This is another judgment call, but as this wasn&#39;t a MUST in the first
place, we weren&#39;t really preventing an attack.  This just removes the
recommendation to remove NEW_TOKEN tokens from Initial packets to new
server addresses.

It leaves the generic guidance, which is far more nuanced.

I&#39;ve added some commentary about the effect of withholding tokens on
performance, as it seems like that is worth highlighting here.

All in all, this leans more toward saying that request forgery is not
the responsibility of QUIC deployments.

Closes #4076.
You can view, comment on, or merge this pull request online at:

  https://github.com/quicwg/base-drafts/pull/4089

-- Commit Summary --

  * Remove recommendation to not include tokens

-- File Changes --

    M draft-ietf-quic-transport.md (14)

-- Patch Links --

https://github.com/quicwg/base-drafts/pull/4089.patch
https://github.com/quicwg/base-drafts/pull/4089.diff

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/4089

----==_mimepart_5f59d2d915e6a_51c719f0515545
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p>This is another judgment call, but as this wasn't a MUST in the first<br>
place, we weren't really preventing an attack.  This just removes the<br>
recommendation to remove NEW_TOKEN tokens from Initial packets to new<br>
server addresses.</p>
<p>It leaves the generic guidance, which is far more nuanced.</p>
<p>I've added some commentary about the effect of withholding tokens on<br>
performance, as it seems like that is worth highlighting here.</p>
<p>All in all, this leans more toward saying that request forgery is not<br>
the responsibility of QUIC deployments.</p>
<p><span class="issue-keyword tooltipped tooltipped-se" aria-label="This pull request closes issue #4076.">Closes</span> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="695389775" data-permission-text="Title is private" data-url="https://github.com/quicwg/base-drafts/issues/4076" data-hovercard-type="issue" data-hovercard-url="/quicwg/base-drafts/issues/4076/hovercard" href="https://github.com/quicwg/base-drafts/issues/4076">#4076</a>.</p>

<hr>

<h4>You can view, comment on, or merge this pull request online at:</h4>
<p>&nbsp;&nbsp;<a href='https://github.com/quicwg/base-drafts/pull/4089'>https://github.com/quicwg/base-drafts/pull/4089</a></p>

<h4>Commit Summary</h4>
<ul>
  <li>Remove recommendation to not include tokens</li>
</ul>

<h4>File Changes</h4>
<ul>
  <li>
    <strong>M</strong>
    <a href="https://github.com/quicwg/base-drafts/pull/4089/files#diff-db016291106766877c4921a79f8596e0">draft-ietf-quic-transport.md</a>
    (14)
  </li>
</ul>

<h4>Patch Links:</h4>
<ul>
  <li><a href='https://github.com/quicwg/base-drafts/pull/4089.patch'>https://github.com/quicwg/base-drafts/pull/4089.patch</a></li>
  <li><a href='https://github.com/quicwg/base-drafts/pull/4089.diff'>https://github.com/quicwg/base-drafts/pull/4089.diff</a></li>
</ul>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/quicwg/base-drafts/pull/4089">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AFTOJKZ5WZZ72DH3C7V5PQTSFB4NTANCNFSM4RENVPHQ">unsubscribe</a>.<img src="https://github.com/notifications/beacon/AFTOJK2SVEIHKUK56DHSRV3SFB4NTA5CNFSM4RENVPH2YY3PNVWWK3TUL52HS4DFUVEXG43VMWVGG33NNVSW45C7NFSM4KMTTCVA.gif" height="1" width="1" alt="" /></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/quicwg/base-drafts/pull/4089",
"url": "https://github.com/quicwg/base-drafts/pull/4089",
"name": "View Pull Request"
},
"description": "View this Pull Request on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>

----==_mimepart_5f59d2d915e6a_51c719f0515545--

