Re: Consensus to delete Obfuscated CID?

Nick Harper <nharper@google.com> Wed, 29 July 2020 19:03 UTC

Return-Path: <nharper@google.com>
X-Original-To: quic@ietfa.amsl.com
Delivered-To: quic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E35C3A0E36 for <quic@ietfa.amsl.com>; Wed, 29 Jul 2020 12:03:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.6
X-Spam-Level:
X-Spam-Status: No, score=-17.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FMjTEsf7yHZJ for <quic@ietfa.amsl.com>; Wed, 29 Jul 2020 12:03:46 -0700 (PDT)
Received: from mail-ot1-x32b.google.com (mail-ot1-x32b.google.com [IPv6:2607:f8b0:4864:20::32b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E9703A0E50 for <quic@ietf.org>; Wed, 29 Jul 2020 12:02:58 -0700 (PDT)
Received: by mail-ot1-x32b.google.com with SMTP id a65so9125546otc.8 for <quic@ietf.org>; Wed, 29 Jul 2020 12:02:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=kr9VI2+A4pzlkcTBM8JWA5ST3vOZlCjLQmEwtp/jJ9w=; b=o/aztz0AEDRMsi7E+HN7A8rySzVh7npw0BsCMOPpDAuivlfjcc3GitRyyd/iGu3oGN vKI1ze4wXWx3wZuAeI8wgudhgPpKDZ8okCsjsNvdrp8/3zvpisLJKCSMSqzzjMTdqO8B fdeThzaZkzJOV5BmZPnl1TwQ9+8PZ7f8qAjde5JlZbPcOKwei2Pn2LdpyqV36ip/79sK Fj6NKPS2pVgcuBWgdLyojuEhCh0eqiCLuYnrEMUToyww8xB8EbYjPWgYJc/PAToFmctd TlvfvUyf6Sp0ruxIiorY8d1NZVU8aTgdp/X7UNbew7oavNl3d1QFqBJNVc/qAWhRsILC uwoQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=kr9VI2+A4pzlkcTBM8JWA5ST3vOZlCjLQmEwtp/jJ9w=; b=tjYzHy8UIGfwZApFENSCM0FFEeMjiAFWikR4VVqQcP6BUc0KO/BmVTRpb0iT/fE8P7 SVIOm4YcK63d90MYz62ht+jkMiOiVtRWRmhA/z2Qzo4v88w2hHnh7Y3uc1c4dUzyQbsA eQ/HRtftwxMJSt6aE0wmsEGuV9tg3BFx/n6G7QEAI1bAKz2ad69amcrZ70/rDuh8zvyL z/zN43HN3HSRw1UxI+ZPImI3lJ6Ifh94widzDs7uhzamq5nzBxXBJ5ETfSxtUCHlsnSB rTgJPMuij89jcTenCGUg+hoF1kR14YdwMjgWNLBTLVOvL9OGF2uy8CzeZrDrOspVk4Me xtZg==
X-Gm-Message-State: AOAM5304UiEhJncsdJ/lYaLZtRn2u5KdzEsUa6bOrB+i93NhH4YuA37u Mx6MecbwNTr/JmXKLqWmM7JY0mqwVj5DDycrrhZ9Cg==
X-Google-Smtp-Source: ABdhPJw0A24HGsIDe5ljju2XLGjvTd1TR0VmS5aM7lwzLZYllX8LAWt6EeSlxPLX5B6XdiU5oZ8Du9M8XNA92tlsnpo=
X-Received: by 2002:a05:6830:1d6c:: with SMTP id l12mr29336164oti.275.1596049376786; Wed, 29 Jul 2020 12:02:56 -0700 (PDT)
MIME-Version: 1.0
References: <CAM4esxR82Nwv3LgEv_Wx-ExAvbt88gSPB=YkV97iy8F9t_uGPw@mail.gmail.com>
In-Reply-To: <CAM4esxR82Nwv3LgEv_Wx-ExAvbt88gSPB=YkV97iy8F9t_uGPw@mail.gmail.com>
From: Nick Harper <nharper@google.com>
Date: Wed, 29 Jul 2020 12:02:45 -0700
Message-ID: <CACdeXiJiRLyJP+pAVwBMZNxcqQuRRakkgzFqKTVvMY9z17BW=w@mail.gmail.com>
Subject: Re: Consensus to delete Obfuscated CID?
To: Martin Duke <martin.h.duke@gmail.com>
Cc: IETF QUIC WG <quic@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000261e6505ab99344a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/n-T_69-HS6AFowUaj62kEPHGrJs>
X-BeenThere: quic@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic>, <mailto:quic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic/>
List-Post: <mailto:quic@ietf.org>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic>, <mailto:quic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Jul 2020 19:03:47 -0000

Let's delete it.

On Wed, Jul 29, 2020 at 12:00 PM Martin Duke <martin.h.duke@gmail.com>
wrote:

> The sense of the room today was that the Obfuscated CID algorithm was
> perhaps the worst of all worlds: complicated and fake-secure. I got
> feedback that if we're going to be insecure, just do so explicitly with
> plaintext.
>
> Before I delete a ton of text and code, are there any objections to doing
> this?
>