[rtcweb] 答复: 答复: Fwd: I-D Action: draft-westerlund-rtcweb-codec-control-00.txt

邓灵莉/denglingli <denglingli@chinamobile.com> Tue, 22 May 2012 01:29 UTC

Return-Path: <denglingli@chinamobile.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 423D721F8569 for <rtcweb@ietfa.amsl.com>; Mon, 21 May 2012 18:29:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.728
X-Spam-Level: ***
X-Spam-Status: No, score=3.728 tagged_above=-999 required=5 tests=[AWL=1.239, BAYES_40=-0.185, MIME_8BIT_HEADER=0.3, RELAY_IS_221=2.222, SARE_SUB_ENC_UTF8=0.152]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GTEeSZjecd2v for <rtcweb@ietfa.amsl.com>; Mon, 21 May 2012 18:29:17 -0700 (PDT)
Received: from imss.chinamobile.com (imss.chinamobile.com [221.130.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id 9DF3321F8562 for <rtcweb@ietf.org>; Mon, 21 May 2012 18:29:13 -0700 (PDT)
Received: from imss.chinamobile.com (localhost [127.0.0.1]) by localhost.chinamobile.com (Postfix) with ESMTP id 31502E423; Tue, 22 May 2012 09:29:10 +0800 (CST)
Received: from mail.chinamobile.com (unknown [10.1.28.22]) by imss.chinamobile.com (Postfix) with ESMTP id 29A67E41B; Tue, 22 May 2012 09:29:10 +0800 (CST)
Received: from denglingli ([10.2.43.107]) by mail.chinamobile.com (Lotus Domino Release 6.5.6) with ESMTP id 2012052209290741-4722 ; Tue, 22 May 2012 09:29:07 +0800
From: 邓灵莉/denglingli <denglingli@chinamobile.com>
To: 'Martin Thomson' <martin.thomson@gmail.com>, 'Magnus Westerlund' <magnus.westerlund@ericsson.com>
References: <20120516140228.4049.34228.idtracker@ietfa.amsl.com> <4FB3B55F.3080607@ericsson.com> <003f01cd36f3$5302aed0$f9080c70$@chinamobile.com> <4FB9E79C.1050300@ericsson.com> <CABkgnnUs4K3aP7Ge4+sQ7e6UDEwx-hGJi50Tn6hG4rEwiz98HQ@mail.gmail.com>
In-Reply-To: <CABkgnnUs4K3aP7Ge4+sQ7e6UDEwx-hGJi50Tn6hG4rEwiz98HQ@mail.gmail.com>
Date: Tue, 22 May 2012 09:25:56 +0800
Message-ID: <001901cd37b9$d66c9490$8345bdb0$@chinamobile.com>
MIME-Version: 1.0
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQFH7Hy2W/WGRSF2rP61qjwTRiq8KwG+VZYhAbFyGeYBiDdXHAHH0ykgl6maOnA=
X-MIMETrack: Itemize by SMTP Server on jtgsml01/servers/cmcc(Release 6.5.6|March 06, 2007) at 2012-05-22 09:29:07, Serialize by Router on jtgsml01/servers/cmcc(Release 6.5.6|March 06, 2007) at 2012-05-22 09:29:10, Serialize complete at 2012-05-22 09:29:10
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
Content-Language: zh-cn
X-TM-AS-Product-Ver: IMSS-7.0.0.8231-6.8.0.1017-18920.001
X-TM-AS-Result: No--22.034-7.0-31-10
X-imss-scan-details: No--22.034-7.0-31-10;No--22.034-7.0-31-10
X-TM-AS-User-Approved-Sender: No;No
X-TM-AS-User-Blocked-Sender: No;No
Cc: rtcweb@ietf.org
Subject: [rtcweb] 答复: 答复: Fwd: I-D Action: draft-westerlund-rtcweb-codec-control-00.txt
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 May 2012 01:29:18 -0000

Hi, Martin

You are right. According to the current discussion, I would suggest two options about the security threat statement: 
1, remove the item c from Section 8; or
2, add a few words to notify what is left out and may be of concern in the field and people would know what to expect in reality.
Would you agree?

BR 
Lingli

-----邮件原件-----
发件人: Martin Thomson [mailto:martin.thomson@gmail.com] 
发送时间: 2012年5月21日 23:43
收件人: Magnus Westerlund
抄送: 邓灵莉/denglingli; rtcweb@ietf.org
主题: Re: [rtcweb] 答复: Fwd: I-D Action: draft-westerlund-rtcweb-codec-control-00.txt

> On 2012-05-21 03:44, 邓灵莉/denglingli wrote:
>> That the initial downgrading of the combined potential ceiling for 
>> collected parameters for media quality (codec capabilities plus COP 
>> parameters as stated in Section 5) through SDP transaction by a malicious participant.

As Magnus pointed out, this is true of anything that can be signaled.
The application can do anything up to (and including) a complete denial of service.  The fact that the application is effectively the victim of this attack means that we probably shouldn't concern ourselves overmuch.

__________ Information from ESET NOD32 Antivirus, version of virus signature database 7138 (20120515) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com