Re: Structuring the BKK spin bit discussion

Martin Thomson <> Tue, 30 October 2018 22:55 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id C4DBD127133 for <>; Tue, 30 Oct 2018 15:55:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id K4P6PD1-kgaS for <>; Tue, 30 Oct 2018 15:55:43 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:4864:20::336]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id E78AB124BE5 for <>; Tue, 30 Oct 2018 15:55:42 -0700 (PDT)
Received: by with SMTP id p23so12785641otf.11 for <>; Tue, 30 Oct 2018 15:55:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=OolWPUeB3OyXVME6fj3XOAkoB+SmIiTxaKvRoyE4whI=; b=R9AgJ5LF9bUyy73a6m3mFlhZLbsER1PRCaZQf8/U47mEQmvA6PkR+TzwufLumP+n7J 6hpX8VwM84UFXViBM6hLmE+Wuze3JTD2vzwBf156Hb8IPsa5HT2huSgSp7d2a70k3Y4j p6RS5zLeIdbVZE7jlD9zxhQyayp7OFRo1K+XI3YGllo6T0/qpTI1QrSKVPwvK1svvvim JuLfIVB+D4GEBmpltW9FhmG/qfWp8LalVszVXSzdEfv7iL4KzhLfoK3X+LxlLal7OXUo Pm4Ae3Yu5dfybgW67TsozIz0XFDYqPmFKVxaQFLS2EouPBYJjXNYlKMVhvayMuxKuSFE gO9A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=OolWPUeB3OyXVME6fj3XOAkoB+SmIiTxaKvRoyE4whI=; b=qvqrQIFwKilphPQ9sqnxw7C0ybKPpd1WHJZYXf+qXDSMoHqSmlcdvEa97Xc7i52rg/ kgCAzSnWc7OEKUG85LJ51zihkotRKJnWkCEP4x8QgNO3MXBSLYpR+eQi77kOSq0/mDxA 0m0upXEguJT6lUfTP4k6+z//lYFdzJEtj0xsZYYiWYtRtt815p8mtSEscgRlfRr3K5vg YqiUV/+kqyycaqxmtYrNHYgaVetyK93ZlApyaA83LfksUAIMH8I+kjQKqG+DZ1DjQw9+ 8hInOQUYLDs37ipWi5VOn4Bpwqtht6dUr5aMFSA3mCixlIh5ZWYO8IZ3/n5FHvZoNYZ3 PHHg==
X-Gm-Message-State: AGRZ1gKngtoP1/5Mdyqj7eCvUIS8meiKFT/B/U50d2BxXXT8tOz7MMFJ am/3aFDmLKjWUOKw55jZDsPoQNLuCwJcTT8DlD6+e+ss
X-Google-Smtp-Source: AJdET5cXEKA5LfCyhZIyrzj8KRNWJ+ssyYslQL4Gdm+OoMS5c8+LPTOsU5KkOZ+IIaTEorH/oyrMzD8k/SWh5IbjoVo=
X-Received: by 2002:a9d:6101:: with SMTP id i1mr439102otj.310.1540940142225; Tue, 30 Oct 2018 15:55:42 -0700 (PDT)
MIME-Version: 1.0
References: <> <20181029160802.GD7258@ubuntu-dmitri> <> <> <> <> <DB6PR10MB1766E6B29792BB4401FF38F0ACCC0@DB6PR10MB1766.EURPRD10.PROD.OUTLOOK.COM> <> <>
In-Reply-To: <>
From: Martin Thomson <>
Date: Wed, 31 Oct 2018 09:55:33 +1100
Message-ID: <>
Subject: Re: Structuring the BKK spin bit discussion
To: Christian Huitema <>
Cc: Marcus Ihlar <>, Mikkel Fahnøe Jørgensen <>, QUIC WG <>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <>
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 30 Oct 2018 22:55:45 -0000

On Wed, Oct 31, 2018 at 5:42 AM Christian Huitema <> wrote:
> Mikkel is correct, we may not want a purely random per connection behavior, but rather something "random per destination". This would better mimic the opt-out behavior of a privacy-sensitive endpoint, which would always opt out when contacting a specific destination. If I had to implement it, I would not use a PRNG, but rather something compute the hash of a local secret and either the peer address or the peer name. That way, the client would opt out for all 16 Netflix connections, or for none of them.

Or are we looking for random per-path?

That notion would seem to tilt the balance more in favour of the
"discretionary" option over the "negotiated" one on the basis that
spinning/not doesn't become a linkability consideration.