Re: [rtcweb] Resolving RTP/SDES question in Paris

Iñaki Baz Castillo <ibc@aliax.net> Mon, 19 March 2012 17:20 UTC

Return-Path: <ibc@aliax.net>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F55721F8852 for <rtcweb@ietfa.amsl.com>; Mon, 19 Mar 2012 10:20:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.624
X-Spam-Level:
X-Spam-Status: No, score=-2.624 tagged_above=-999 required=5 tests=[AWL=0.053, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vA8e8fv9RrIx for <rtcweb@ietfa.amsl.com>; Mon, 19 Mar 2012 10:20:33 -0700 (PDT)
Received: from mail-vb0-f44.google.com (mail-vb0-f44.google.com [209.85.212.44]) by ietfa.amsl.com (Postfix) with ESMTP id 6704B21F87D4 for <rtcweb@ietf.org>; Mon, 19 Mar 2012 10:20:33 -0700 (PDT)
Received: by vbbez10 with SMTP id ez10so830694vbb.31 for <rtcweb@ietf.org>; Mon, 19 Mar 2012 10:20:33 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:content-transfer-encoding:x-gm-message-state; bh=8EE1amMHCgkRT1zx9uvIbwLjOoknpB0XBAcmk7vHH7Q=; b=FH6yjjnwtNDxkT6n8lHJ0im1etePEnOk5zh1i5ZKc7rkqVbQrf+W2tGam3GeJVhgQs 4geWMXZYWRk0N09Wv6nKDCKS+s+1ZS4dUuCLPIJxBj+xRPjW6EtpIFKcQ74BCEmJo7E6 dzAEFNIkROQYovetvUJJNn1qNnO/7renzmMfIf6cv0ekhFHZiBz/3rS+q6CZ297u+FNT 8LYhtWR3nuvqHIHRzmZRSo17ezCueJrUrTQV8m6ahq6IEskpzBCPGh8hSeHBwleD3QDP iKF61wpRK4JYpILlvDl2ohlYeOj4fc2NdfT1iSzjtm9huQvFdAWUjNZwvFQi590+2O40 fYkw==
Received: by 10.52.90.111 with SMTP id bv15mr6086904vdb.34.1332177632937; Mon, 19 Mar 2012 10:20:32 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.52.170.165 with HTTP; Mon, 19 Mar 2012 10:20:12 -0700 (PDT)
In-Reply-To: <CAD5OKxvuEV8Vbq3h7=ZgcKmREjmguvz5n-SpXr2n-EY7a_ddxg@mail.gmail.com>
References: <4F4759DC.7060303@ericsson.com> <387F9047F55E8C42850AD6B3A7A03C6C0E1FEB69@inba-mail01.sonusnet.com> <CALiegfnkYVEpmPV-zSL_4wOY-HiFZN-qJCQCiioaS=5NaqhLZw@mail.gmail.com> <CAD5OKxvtOAxMBx6xDnyfTnEq76oDEm6uj1xL6wGjjrtKUAHy3g@mail.gmail.com> <CABcZeBNZiotPmCfT53uEo+O0xw4xv6tXW1M_G-3A5BHuncsduA@mail.gmail.com> <CAD5OKxvYOY5JZ2mYNGiH1poUBQkyOOycePFijH5H+SxtcdqujQ@mail.gmail.com> <CABkgnnVe-b6Sv=R67bMJk_NQqQwdrRUn6rBm7Gu_CMcfPQwtEg@mail.gmail.com> <CAD5OKxvZbEJ7sV4WPAYoQapzMR_QwAftj-oKg=ioMKHNT792wQ@mail.gmail.com> <6F428EFD2B8C2F49A2FB1317291A76C113563C5A92@USNAVSXCHMBSA1.ndc.alcatel-lucent.com> <CALiegf=jtkDCS_D0ZFe9UpbiadQ0vsJ+4MppQSbLr-wbaXNrfQ@mail.gmail.com> <BLU169-W29E5B86F9E2C6F3126961C93420@phx.gbl> <CALiegfk2aT+6Psr4nT-hG1G7eYRBfFCcT+25On2O4HfUXJ6-ng@mail.gmail.com> <CAD6AjGSmi9j+sdGWPts20-iwGvGij05ek0OKYEPULC6B=aFpQg@mail.gmail.com> <6F428EFD2B8C2F49A2FB1317291A76C113564482A7@USNAVSXCHMBSA1.ndc.alcatel-lucent.com> <ADBB75F3-E20C-4EC4-B9C3-EF2E4BFF409C@phonefromhere.com> <CAD5OKxvuEV8Vbq3h7=ZgcKmREjmguvz5n-SpXr2n-EY7a_ddxg@mail.gmail.com>
From: Iñaki Baz Castillo <ibc@aliax.net>
Date: Mon, 19 Mar 2012 18:20:12 +0100
Message-ID: <CALiegfk1ozOKPcDjbd3H_z2Edzh4RcZpYyJSWdw_1DJ04muQXA@mail.gmail.com>
To: Roman Shpount <roman@telurix.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQlbrY+1L6e6ranzRhfWyyH3teWIHHugMwdsJ5hqRmMqfsGQpGTjkVMbQ/qsNhvaoNJZU+9I
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] Resolving RTP/SDES question in Paris
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Mar 2012 17:20:34 -0000

2012/3/19 Roman Shpount <roman@telurix.com>:
> In this case the simplest way to compromise your security is to seat next to
> you. Your first hop is between your mouth and the microphone. Or between
> your screen and your face.

You can control that (you know whether there is people hearing you or
not, or at least you can check it). But if you are using plain RTP in
an open WiFi connection you have no way to determine whether somebody
in the floor above/below is intercepting your RTP.

If your argument would be valid, then HTTPS is useless since somebody
could seat near you and watch your screen. Ok, let's focus the real
discussion...

-- 
Iñaki Baz Castillo
<ibc@aliax.net>