Re: [rtcweb] Summary of ICE discussion
Harald Alvestrand <harald@alvestrand.no> Wed, 05 October 2011 15:48 UTC
Return-Path: <harald@alvestrand.no>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 290FE21F8CEA for <rtcweb@ietfa.amsl.com>; Wed, 5 Oct 2011 08:48:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -108.735
X-Spam-Level:
X-Spam-Status: No, score=-108.735 tagged_above=-999 required=5 tests=[AWL=1.863, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NhZAzRE3gzq6 for <rtcweb@ietfa.amsl.com>; Wed, 5 Oct 2011 08:48:18 -0700 (PDT)
Received: from eikenes.alvestrand.no (eikenes.alvestrand.no [158.38.152.233]) by ietfa.amsl.com (Postfix) with ESMTP id 0A3E421F8CF2 for <rtcweb@ietf.org>; Wed, 5 Oct 2011 08:48:18 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id DBE3A39E0A7 for <rtcweb@ietf.org>; Wed, 5 Oct 2011 17:51:25 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at eikenes.alvestrand.no
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RaDx3hmXxI4S for <rtcweb@ietf.org>; Wed, 5 Oct 2011 17:51:24 +0200 (CEST)
Received: from [172.16.41.139] (unknown [74.125.121.33]) by eikenes.alvestrand.no (Postfix) with ESMTPS id 7C25739E048 for <rtcweb@ietf.org>; Wed, 5 Oct 2011 17:51:24 +0200 (CEST)
Message-ID: <4E8C7CFB.2060904@alvestrand.no>
Date: Wed, 05 Oct 2011 17:51:23 +0200
From: Harald Alvestrand <harald@alvestrand.no>
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.23) Gecko/20110921 Thunderbird/3.1.15
MIME-Version: 1.0
To: rtcweb@ietf.org
References: <4E8B192E.80809@ericsson.com> <CALiegfmnxO+BrfycOmL=hptBFdcEpsLeBn=zsJTX=ivKBBumWw@mail.gmail.com> <BLU152-W139AA2913C1CFFDB50726193FB0@phx.gbl> <BLU152-W2342F5823933FA1F2B9F9C93FB0@phx.gbl> <37C37EE6-3D48-4C77-A025-3207F040572B@cisco.com> <4E8BC56E.40306@skype.net> <snt0-eas2567EB3C48B254DA9E07FC693F80@phx.gbl>, <4E8C10BC.8090104@ericsson.com> <BLU152-W463B7BC9EE2E0FEB96B3C593F80@phx.gbl>
In-Reply-To: <BLU152-W463B7BC9EE2E0FEB96B3C593F80@phx.gbl>
Content-Type: multipart/alternative; boundary="------------050601060406040002020309"
Subject: Re: [rtcweb] Summary of ICE discussion
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Oct 2011 15:48:19 -0000
On 10/05/2011 05:35 PM, Bernard Aboba wrote: > What I was trying to point out was that there are very specific conditions > under which the browser will consider the STUN exchange to be > "successful" that > will not be met by a public STUN server, which typically will not > support ICE > extensions. If we articulate this, it would not be possible to DoS a > public STUN > server with *media*, which has been the bar we've been applying so far. Indeed, a public STUN server will not be configured with an username / password (RFC 5245 section 7.1.2.3), and thus its answers will not pass the ICE check for a correct MIC. > > It should be understood that when the "answer" is not directly > available to the > offering browser, the STUN exchange is only able to verify the > willingness > to receive on a particular IP address/port combination. Without > multi-plexing, > this should ensure that the receiver has consented to each media type. > Assuming that we can satisfactorily handle "continuing consent" > determination, > I'm not sure that we would need ICE extensions to address the issue. > This seems like a slippery slope that could result in a continuing > stream of > ICE extensions. > > IMHO, the "congestion control" problem is separable. Since > it seems inevitable that RTCWeb implementations will support > non-adaptive codecs, I don't believe we can rely on "congestion > control" for DoS avoidance. The control I was thinking of is that when a Javascript DoS attacker attempts to send media to a DoS victim at some significant traffic volume, the DoS victim can send back a TMMBR saying "I only want this much data" (where "this much" is a reasonable amount for the media types it's been expecting). That won't solve large scale DDoS attacks, of course, but at least it is pushback against the "I said yes to 32 Kbits and you hit me with 2 Mbits" attacks. > > > > Date: Wed, 5 Oct 2011 10:09:32 +0200 > > From: magnus.westerlund@ericsson.com > > To: bernard_aboba@hotmail.com > > CC: matthew.kaufman@skype.net; rtcweb@ietf.org > > Subject: Re: [rtcweb] Summary of ICE discussion > > > > Hi, > > > > good that my summary lets us move forward. > > > > A question on this attack. How common is it that these STUN servers use > > other ports than 3478? Would a rule about that port mitigate the issue, > > even if it could result in connectivity failures in cases where the NAT > > external port is 3478 by chance? > > > > In addition does these public servers use the username and password > > convention from ICE? Isn't that what prevents STUN server deployed for > > just determining your server reflexive candidate from actually respond > > correctly to a connectivity check? As ICE do concatenate one part > > generated by one peer with a part generated by the other peer I don't > > see this as an issue as long as the random username fragment is > > generated by the browser not the JS. > > > > Cheers > > > > Magnus Westerlund > > > > ---------------------------------------------------------------------- > > Multimedia Technologies, Ericsson Research EAB/TVM > > ---------------------------------------------------------------------- > > Ericsson AB | Phone +46 10 7148287 > > Färögatan 6 | Mobile +46 73 0949079 > > SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com > > ---------------------------------------------------------------------- > > > > > _______________________________________________ > rtcweb mailing list > rtcweb@ietf.org > https://www.ietf.org/mailman/listinfo/rtcweb
- Re: [rtcweb] Summary of ICE discussion Randell Jesup
- [rtcweb] Summary of ICE discussion Magnus Westerlund
- Re: [rtcweb] Summary of ICE discussion Iñaki Baz Castillo
- Re: [rtcweb] Summary of ICE discussion Randell Jesup
- Re: [rtcweb] Summary of ICE discussion Olle E. Johansson
- Re: [rtcweb] Summary of ICE discussion Eric Rescorla
- Re: [rtcweb] Summary of ICE discussion Cary Bran (cbran)
- Re: [rtcweb] Summary of ICE discussion Hadriel Kaplan
- Re: [rtcweb] Summary of ICE discussion Bernard Aboba
- Re: [rtcweb] Summary of ICE discussion Bernard Aboba
- Re: [rtcweb] Summary of ICE discussion Cullen Jennings
- Re: [rtcweb] Summary of ICE discussion Cullen Jennings
- Re: [rtcweb] Summary of ICE discussion Matthew Kaufman
- Re: [rtcweb] Summary of ICE discussion Matthew Kaufman
- Re: [rtcweb] Summary of ICE discussion Matthew Kaufman
- Re: [rtcweb] Summary of ICE discussion Bernard Aboba
- Re: [rtcweb] Summary of ICE discussion Matthew Kaufman
- Re: [rtcweb] Summary of ICE discussion Ravindran Parthasarathi
- Re: [rtcweb] Summary of ICE discussion Roman Shpount
- Re: [rtcweb] Summary of ICE discussion Magnus Westerlund
- Re: [rtcweb] Summary of ICE discussion Magnus Westerlund
- Re: [rtcweb] Summary of ICE discussion Harald Alvestrand
- Re: [rtcweb] Summary of ICE discussion Harald Alvestrand
- Re: [rtcweb] Summary of ICE discussion Jonathan Lennox
- Re: [rtcweb] Summary of ICE discussion Ravindran Parthasarathi
- Re: [rtcweb] Summary of ICE discussion Bernard Aboba
- Re: [rtcweb] Summary of ICE discussion Harald Alvestrand
- Re: [rtcweb] Summary of ICE discussion Cullen Jennings
- Re: [rtcweb] Summary of ICE discussion Paul Hoffman
- Re: [rtcweb] Summary of ICE discussion sebastien.cubaud
- Re: [rtcweb] Summary of ICE discussion Iñaki Baz Castillo
- [rtcweb] Sebastien Cubaud's non-ICE mechanism (Re… Harald Alvestrand
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… sebastien.cubaud
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Eric Rescorla
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Iñaki Baz Castillo
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Randell Jesup
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Jonathan Rosenberg
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Randell Jesup
- Re: [rtcweb] Summary of ICE discussion sebastien.cubaud
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Iñaki Baz Castillo
- Re: [rtcweb] Summary of ICE discussion Iñaki Baz Castillo
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Tim Panton
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… sebastien.cubaud
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… Muthu Arul Mozhi Perumal (mperumal)
- Re: [rtcweb] Sebastien Cubaud's non-ICE mechanism… sebastien.cubaud
- Re: [rtcweb] Summary of ICE discussion sebastien.cubaud