Re: [rtcweb] Resolving RTP/SDES question in Paris

Iñaki Baz Castillo <ibc@aliax.net> Sat, 17 March 2012 16:33 UTC

Return-Path: <ibc@aliax.net>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ECAE121F84F6 for <rtcweb@ietfa.amsl.com>; Sat, 17 Mar 2012 09:33:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.614
X-Spam-Level:
X-Spam-Status: No, score=-2.614 tagged_above=-999 required=5 tests=[AWL=0.063, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0yA77Ub4DAKV for <rtcweb@ietfa.amsl.com>; Sat, 17 Mar 2012 09:33:43 -0700 (PDT)
Received: from mail-vx0-f172.google.com (mail-vx0-f172.google.com [209.85.220.172]) by ietfa.amsl.com (Postfix) with ESMTP id 1F14B21F84B4 for <rtcweb@ietf.org>; Sat, 17 Mar 2012 09:33:43 -0700 (PDT)
Received: by vcbfk13 with SMTP id fk13so6332234vcb.31 for <rtcweb@ietf.org>; Sat, 17 Mar 2012 09:33:41 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:content-transfer-encoding:x-gm-message-state; bh=z8PLBPj5Pgam46xxAMw7VHlpti0I9GvKv7y+isT9bic=; b=DxnccObhVHXIy4UW2kty9LxQWMqBZLuMlpOoLz6qMcaZ91HaNDwKSUEPrn2CyczlHc OvGTU7mbjA3izMa9TrU2eVCTb3Z8OQK4XAP1kX6T9qVsG4EYi7XOUOob0PLClZyzuQLO z5IPHgJqaroQbjs1TPhPmijjcZSlacKfDozYjfUj0vMWvdLEgcvE0T6Il0FItfYbbzsu pek1+KqJNDeEdJeqMzNHfKUJBf6dm/jyMa+a4737Xy38T4MfabusSf+d6I0GO/dWkDLq ksJTi65IOWuqs4boSpMAiwUypluQvOrrLhFMh2G9Oi/OtSOouE9i02rnWBV/QcyYWQBk c9kQ==
Received: by 10.220.116.20 with SMTP id k20mr2298964vcq.54.1332002021512; Sat, 17 Mar 2012 09:33:41 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.52.165.162 with HTTP; Sat, 17 Mar 2012 09:33:21 -0700 (PDT)
In-Reply-To: <387F9047F55E8C42850AD6B3A7A03C6C0E1FEC15@inba-mail01.sonusnet.com>
References: <4F4759DC.7060303@ericsson.com> <387F9047F55E8C42850AD6B3A7A03C6C0E1FEB69@inba-mail01.sonusnet.com> <4F63BA4E.305@jesup.org> <387F9047F55E8C42850AD6B3A7A03C6C0E1FEC15@inba-mail01.sonusnet.com>
From: Iñaki Baz Castillo <ibc@aliax.net>
Date: Sat, 17 Mar 2012 17:33:21 +0100
Message-ID: <CALiegfmp5B7qWayfyqp6FvsnjKTQ=J5126RNzrtw9=Zw1+aLJw@mail.gmail.com>
To: "Ravindran, Parthasarathi" <pravindran@sonusnet.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQneze8RP8ORIugUwFBUZQ5pU/GsOnxhViEP53h7FXRus/3a025LT16sq6SGf/cdcQF2I4TU
Cc: Randell Jesup <randell-ietf@jesup.org>, "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] Resolving RTP/SDES question in Paris
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 17 Mar 2012 16:33:44 -0000

2012/3/17 Ravindran, Parthasarathi <pravindran@sonusnet.com>:
> In my usecase, the application will not be able to access the website without VPN connection . Please explain your bid-down attack in my usecase.

IMHO the topic here is not about finding a usecase in which using
plain RTP is secure (as in your example involving a VPN). Rather, the
topic is about finding common usecases in which the end user joins
unsecure media communications without the proper knowledge of "what
that means" so it accepts it. If the security depends on the end user
approval ("this web site does not provide secure audio/video
communications, do you accept it?") the we are lost (IMHO).

-- 
Iñaki Baz Castillo
<ibc@aliax.net>