Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusic-encrypted-ice-candidates

Sean DuBois <> Mon, 11 November 2019 09:04 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 8DD0E120898 for <>; Mon, 11 Nov 2019 01:04:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 360wGQd8pRUe for <>; Mon, 11 Nov 2019 01:03:59 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4864:20::441]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 8F883120897 for <>; Mon, 11 Nov 2019 01:03:59 -0800 (PST)
Received: by with SMTP id q26so10242957pfn.11 for <>; Mon, 11 Nov 2019 01:03:59 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=GYd5AZF17YDjO/Wbhz5IIkDmx1tI1Gb6hxljPYFq29I=; b=F4Vi0GWjkKB3cpvxIDJ2Wr8L3mLW+Rg5D0E7Tu3ocOQ2DA4zHHnNoCeRaSruXcLxiY awqdCzQ6tOTRfAVXKnqbpS2VFI3U4pIqet2T/ymwJdlTYkmxnFA7ajlwDFcXJEJKhEmH l0zvjqKta2Glh9fmISVCEAMLbpznJkkgSxL3VtqejCEh5WZy0XSDTjpg8+OxQi+/D4Yn Bmrq4J9NYlG/ZApHBnZ05NuLlmBlA21da38dE3eEHRhXCkoI4OchnASSxtkSqw1vFEKM JT5rR9GR3JM5BgYsDZ46wDueKmm/AWbosmnpIOo2ryGlzMah/ialLKkjUCGhgwOoWzxf zrzA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=GYd5AZF17YDjO/Wbhz5IIkDmx1tI1Gb6hxljPYFq29I=; b=c7J1PTEk4acwopobETFmR1aFkNHDgnUBaIdLm6kgmE9cE1SjzcG+TH26G3nS3cVPtK CrVpBHoP1WCmBnBJdOHM01aI6jgCEeKNYtL4vOOJQaQkRTeQLxb8TlBHeJ90myLcoOGE ncf3A1n+O8euaC1Qcprnzgd1e0dj6hBHLObOs9KjRCvbL1IYlBVaoJCbEp6hr2HDWv4E 0VQbR4Mqwp+A7TL2oyaIwzaVQLWfWRU5RM3vJWRJu1RK1jqdHfZleG/IfQJNTxy8g53p FK7/kUMco5v1aEPlbY8pjcnjjeNsr8RZAMENGiR4+xxpvoCsuc+q2dLDxKls2ncyVEFY 6yVQ==
X-Gm-Message-State: APjAAAXM8a0e77IC2CWfBMZ+zmALdtSUw3doKp53zvxlXzw/RqDeqnsZ ef4borC8f6cfDSkIPgrnIdrbKg==
X-Google-Smtp-Source: APXvYqwaGRtNbuXZrW7GSV1fY2R5nXXCFnF0JkbFhA912BitBNQTxM3Bq8IpiFAQB1J4TyutL+aFUQ==
X-Received: by 2002:a65:48c7:: with SMTP id o7mr6002658pgs.276.1573463038426; Mon, 11 Nov 2019 01:03:58 -0800 (PST)
Received: from ([]) by with ESMTPSA id q20sm13385494pff.134.2019. (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 11 Nov 2019 01:03:57 -0800 (PST)
Date: Mon, 11 Nov 2019 01:03:56 -0800
From: Sean DuBois <>
To: Qingsi Wang <>
Cc:, Alex Drake <>,
Message-ID: <>
References: <>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
User-Agent: NeoMutt/20180716
Archived-At: <>
Subject: Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusic-encrypted-ice-candidates
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 11 Nov 2019 09:04:04 -0000

On Fri, Nov 01, 2019 at 01:06:22PM -0700, Qingsi Wang wrote:
> Greetings.
> This draft (
> proposes a complementary solution to the mDNS candidate detailed
> in draft-ietf-rtcweb-mdns-ice-candidates, specifically for managed
> networks. IPs of ICE candidates are encrypted via PSK and signaled as
> pseudo-FQDNs in this proposal, and it aims to address the connectivity
> challenge from the mDNS technique in these managed environments. The
> current work on this draft is tracked in
> Regards,
> Qingsi

> _______________________________________________
> rtcweb mailing list


Really excited to see this RFC. This is a real pain point, and glad it
is being addressed. I implemented this over the weekend and everything
fell into place.

Have you thought about/explored encrypting the entire SessionDescription?
There might be some issues I am not aware of, but it would give us some
other nice things!

* No more SDP munging (or at least make it harder)
   - People shoot themselves in the foot constantly by editing things
   - Will push people to communicate API needs more, instead of more hacks

* Host candidates aren't the only thing you can be fingerprinted off of
  - Agents craft very different SDPs (FireFox vs Chromium)
  - SDPs reveal hardware attributes (Chromium Android has H264 only with HW Accel)
  - Agent may have different experiments/settings (attributes at session/media level)

* Changes to candidate strings is going to cause more breakage
  Maybe this doesn't matter as much, but I anticipate this is going to
  cause more bugs. Some clients/SFUs/MCUs... blew up when mDNS came out,

  I bet another change is going to cause the same thing. It sounds like
  this will be much less likely because people will need to setup
  something up to get the PSK going.

I would love to see example implementations of the Key Management. Is
there any precedent for configuration of the WebRTC agent in managed