Re: [rtcweb] AVPF [was: Encryption mandate (and offer/answer)]

"Dan Wing" <dwing@cisco.com> Tue, 20 September 2011 23:33 UTC

Return-Path: <dwing@cisco.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FDA31F0C5D for <rtcweb@ietfa.amsl.com>; Tue, 20 Sep 2011 16:33:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.286
X-Spam-Level:
X-Spam-Status: No, score=-103.286 tagged_above=-999 required=5 tests=[AWL=-0.687, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XUUjTK7LLugL for <rtcweb@ietfa.amsl.com>; Tue, 20 Sep 2011 16:33:10 -0700 (PDT)
Received: from mtv-iport-4.cisco.com (mtv-iport-4.cisco.com [173.36.130.15]) by ietfa.amsl.com (Postfix) with ESMTP id CB7BC1F0C36 for <rtcweb@ietf.org>; Tue, 20 Sep 2011 16:33:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=dwing@cisco.com; l=927; q=dns/txt; s=iport; t=1316561736; x=1317771336; h=from:to:cc:references:in-reply-to:subject:date: message-id:mime-version:content-transfer-encoding; bh=w1rw02x9/QN5infkjrhMyMyjxLgtQ1HSzho7mIQrtmg=; b=K0n7huSmS8mQWyUqyFmJvO6jNvDPMieoqLdjRArWbAXtyta1pqendSW4 wxZ3hiF3qwKQ5RA/nEZ1Tfp9J2cwVpq+tEd8tVbrvOS1UzCZrRECrJv2l ZgxW9QiWBunwfHnMMHWfyoEN6MmoTURjX8SSdmQsPA65KQsAVo4jItQNO w=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AqsAAA0jeU6rRDoJ/2dsb2JhbAAoGphygWyNBXiBUwEBAQEBAQEICgEXED8FBwEDAgkPAgQBAQEnBxkjCgkIAQEEEwsXh1UGJJR2AZ4ghn0Eh3CdKQ
X-IronPort-AV: E=Sophos;i="4.68,413,1312156800"; d="scan'208";a="3302630"
Received: from mtv-core-4.cisco.com ([171.68.58.9]) by mtv-iport-4.cisco.com with ESMTP; 20 Sep 2011 23:35:36 +0000
Received: from dwingWS ([128.107.106.61]) by mtv-core-4.cisco.com (8.14.3/8.14.3) with ESMTP id p8KNZZFR008844; Tue, 20 Sep 2011 23:35:35 GMT
From: Dan Wing <dwing@cisco.com>
To: 'Tim Panton' <tim@phonefromhere.com>
References: <A444A0F8084434499206E78C106220CA0B00FDB08B@MCHP058A.global-ad.net> <E4EC1B17-0CC4-4F79-96DD-84E589FCC4F0@edvina.net> <4E67C3F7.7020304@jesup.org> <BE60FA11-8FFF-48E5-9F83-4D84A7FBE2BE@vidyo.com> <4E67F003.6000108@jesup.org> <7F2072F1E0DE894DA4B517B93C6A05852233E8554C@ESESSCMS0356.eemea.ericsson.se> <C3759687E4991243A1A0BD44EAC8230339CA68F054@BE235.mail.lan> <CAOJ7v-2u0UuNXh7bzmZFwiSucbsh=Ps=C3ZM5M3cJrXRmZgODA@mail.gmail.com> <CAKhHsXHXCkNdjtpxCSCk+ABbtxY15GEgouE6X6-sn-LqhnidQw@mail.gmail.com> <4E6A56D4.2030602@skype.net> <CABcZeBOdP6cAqBoiSV-Vdv1_EK3DfgnMamT3t3ccjDOMfELfBw@mail.gmail.com> <CAKhHsXFdU1ZaKQF8hbsOxwTS-_RfmFqQhgzGe=K4mRp+wz+_nQ@mail.gmail.com> <4E6A81EC.3080002@jesup.org>, <4E6AE22A.2070106@alum.mit.edu> <7F2072F1E0DE894DA4B517B93C6A05852233C3B7C5@ESESSCMS0356.eemea.ericsson.se>, <4E6C16FF.1000706@jesup.org> <BBF498F2D030E84AB1179E24D1AC41D61C1BCA829D@ESESSCMS0362.eemea.ericsson.se> <4E6CB9F7.2060208@mozilla.com> <4E6DB7F4.3090404@skype.net> <09b501c c726d$66655360$332ffa 20$@com> <52B1B3C9-A5D2-473A-9A7F-FC7EE6EAD259@phonefromhere.com>
In-Reply-To: <52B1B3C9-A5D2-473A-9A7F-FC7EE6EAD259@phonefromhere.com>
Date: Tue, 20 Sep 2011 16:35:35 -0700
Message-ID: <14cf01cc77ed$ff2808b0$fd781a10$@com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcxzjUrVUk6hk7meSNao0M0K0YEQCgEYJ9yQ
Content-Language: en-us
Cc: rtcweb@ietf.org
Subject: Re: [rtcweb] AVPF [was: Encryption mandate (and offer/answer)]
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2011 23:33:11 -0000

> -----Original Message-----
> From: Tim Panton [mailto:tim@phonefromhere.com]
> Sent: Thursday, September 15, 2011 2:53 AM
> To: Dan Wing
> Cc: 'Matthew Kaufman'; 'Timothy B. Terriberry'; rtcweb@ietf.org
> Subject: Re: [rtcweb] AVPF [was: Encryption mandate (and offer/answer)]
> 
> 
> On 14 Sep 2011, at 00:32, Dan Wing wrote:
> >>
> >
> > SDES is also not as secure as DTLS-SRTP, reference RFC5479.
> >
> > -d
> 
> 
> I had my mind rather forcibly changed on this by reading this:
> https://www.owasp.org/index.php/File:SSL_paved_with_good_intentions.pdf
> and
> http://www.slate.com/id/2265204/
> 
> Basically any key exchange that depends for it's security on https: is
> worthless.

DTLS-SRTP does not validate certificates at all like HTTPS.

-d


> Tim (as usual speaking for himself)
> 
> P.S. I particularly enjoyed the idea of embedding logos in X509 certs
> (seems this is valid).=