Re: [New Issue] CID based attacks

Dmitri Tikhonov <dtikhonov@litespeedtech.com> Thu, 12 November 2020 18:15 UTC

Return-Path: <dtikhonov@litespeedtech.com>
X-Original-To: quic@ietfa.amsl.com
Delivered-To: quic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C66BC3A1476 for <quic@ietfa.amsl.com>; Thu, 12 Nov 2020 10:15:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=litespeedtech-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UNjXzxkQht0l for <quic@ietfa.amsl.com>; Thu, 12 Nov 2020 10:15:13 -0800 (PST)
Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EEB23A1475 for <quic@ietf.org>; Thu, 12 Nov 2020 10:15:13 -0800 (PST)
Received: by mail-qt1-x830.google.com with SMTP id p12so4655660qtp.7 for <quic@ietf.org>; Thu, 12 Nov 2020 10:15:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=litespeedtech-com.20150623.gappssmtp.com; s=20150623; h=date:from:to:subject:message-id:mail-followup-to:references :mime-version:content-disposition:in-reply-to; bh=AGAAwh+E7yOTewkr/ssUdp9vtl0UeldcL6x0+3Ag+zU=; b=RKp2wxrpjj8rWcZtKAvj0WLoebpYI7Zaghs/me5RXHZevdDqeSmWLyB3SEX18aYLZi F7bAJzoAjoIv1q+wilTVxGYHQ530FtMeR3YK8JAPj1zLtFgsQobIM+So4yyvi0lkVFMG PDN7UY82bdTkiCLdreZfmifI/v+t10zzSWKcFvjFaHIqtvMMVxDdu7OvGD1w4vaXyhEk eR+GeMr+PLWvMtvNoxjpbp18/lYVy493LPvdcfCZx1seBNQyKAeZqyXwFHEksAIa/7Fh YYpeuFh5t+Phz+Eilzuza7JGwZd75X7V21UKoZHEhVGTfGxPr3iSmqrNfIVEZT/LuAE2 vUPg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:subject:message-id:mail-followup-to :references:mime-version:content-disposition:in-reply-to; bh=AGAAwh+E7yOTewkr/ssUdp9vtl0UeldcL6x0+3Ag+zU=; b=CA3t/nzL9nYYzELx2FosHx0JKrNOg4bjKLlJ1ylbxlrfAWZh83STcZTBG1ICOeUF0j 0Q/VBt7fsZ0slE1xxD4fZ+CJyANpDkR+fec7lwRZU1GiWCnyWV19Zz7FqaU7Te1FAKtH fim7yx6ZOCEUVKadyKRUE5enDPmgRUyAHxwDsgPXrl+uJb+KZcJjfKpbeFDEFe55/eFQ 1qsgmURZQFG2OxiSaCcYZQMqq51PeCpzAuRE3F3w4OQNlsuuQH3Ia7gVipLs66ziHVe8 4U/kS3JzTrD9wS1pCwjgStdo6yprfBx2GiZ1jGU1U9WDXb9RVq8JW035xcbWS534i6KJ sVTg==
X-Gm-Message-State: AOAM532K239InmCLUgkb/PtG75+rHxbghnSlkez/t4/AqapDcFvirOeM opDwR6dRkwFuccM/v87awGd8E5A8q3oI9Q==
X-Google-Smtp-Source: ABdhPJwe64UeVT0sYGogdwAVTAQiAJGtP9x4NT/lZlUOWyXdKZhyL/CknXy8kaMH4UNrbG8j+TPx8g==
X-Received: by 2002:ac8:74c7:: with SMTP id j7mr392445qtr.179.1605204911898; Thu, 12 Nov 2020 10:15:11 -0800 (PST)
Received: from okhta (ool-44c1d219.dyn.optonline.net. [68.193.210.25]) by smtp.gmail.com with ESMTPSA id n41sm5691419qtb.18.2020.11.12.10.15.10 for <quic@ietf.org> (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 12 Nov 2020 10:15:10 -0800 (PST)
Date: Thu, 12 Nov 2020 13:15:09 -0500
From: Dmitri Tikhonov <dtikhonov@litespeedtech.com>
To: quic@ietf.org
Subject: Re: [New Issue] CID based attacks
Message-ID: <20201112181509.GB98816@okhta>
Mail-Followup-To: quic@ietf.org
References: <e078a391-b8e7-3035-ad3f-848c5effcb2f@informatik.hu-berlin.de>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <e078a391-b8e7-3035-ad3f-848c5effcb2f@informatik.hu-berlin.de>
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/EXdJvtM0QCtWGe-zdqbkA8JRF9Y>
X-BeenThere: quic@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic>, <mailto:quic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic/>
List-Post: <mailto:quic@ietf.org>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic>, <mailto:quic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Nov 2020 18:15:15 -0000

Hello Kashyap,

Thank you for this research.

I will think about the security implications of your research and so I
make no claims about it, but in the meantime, I want quickly to point out
something that you may have missed:

On Thu, Nov 12, 2020 at 05:34:03PM +0100, Kashyap Thimmaraju wrote:
> Hence, I posit the following: If the server (implementation) does not permit
> the use of the same destination CID across successive connections (for a
> specific timeout),

--- 8< --- snip --- 8< ---

> Finally, to obtain the results of the test, I searched the debug log of the
> client or the packet trace to confirm whether the second QUIC connection
> obtained a successful handshake or not. The absence of a successful
> handshake indicates a vulnerable implementation.

After a connection is closed, it may enter the Draining State [1], during
which it will ignore incoming packets with that connection's CIDs for a
period of time.

I can't speak for ATS, Chromium, and ngtcp2, but the failure to handshake
with an already-used DCID with a LiteSpeed server is most likely due to
the Draining State: it simply does not have any other rules precluding
CID reuse.  If you hit up any of the LiteSpeed public interop endpoints
[2] and give me the CID(s) you used, I will look up relevant sections
of the log file and provide them to you.

My question would be:  Why aren't connections in the other 11 implementations
enter the Draining State?

  - Dmitri.

1. https://tools.ietf.org/html/draft-ietf-quic-transport-32#section-10.2.2
2. https://github.com/quicwg/base-drafts/wiki/Implementations#lsquic