Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusic-encrypted-ice-candidates
Harald Alvestrand <harald@alvestrand.no> Mon, 11 November 2019 10:59 UTC
Return-Path: <harald@alvestrand.no>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F31491200CE; Mon, 11 Nov 2019 02:59:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iyhMeDNS4fdM; Mon, 11 Nov 2019 02:59:29 -0800 (PST)
Received: from mork.alvestrand.no (mork.alvestrand.no [IPv6:2001:700:1:2::117]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9928C120255; Mon, 11 Nov 2019 02:59:28 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mork.alvestrand.no (Postfix) with ESMTP id 3DB4F7C4B35; Mon, 11 Nov 2019 11:59:25 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at alvestrand.no
Received: from mork.alvestrand.no ([127.0.0.1]) by localhost (mork.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mltDtr7GWWWD; Mon, 11 Nov 2019 11:59:22 +0100 (CET)
Received: from [192.168.3.17] (unknown [188.113.75.166]) by mork.alvestrand.no (Postfix) with ESMTPSA id B0DE57C39E3; Mon, 11 Nov 2019 11:59:22 +0100 (CET)
To: Sean DuBois <sean@pion.ly>, Qingsi Wang <qingsi=40google.com@dmarc.ietf.org>
Cc: Alex Drake <alexdrake@google.com>, rtcweb@ietf.org, mmusic@ietf.org
References: <CA+m752++Frkcq00Lcg0x6is+cWtg2NNf6unWdEiaG1JwTfNMQw@mail.gmail.com> <20191111090356.mfkn2nbzim7xvhg4@38f9d359441f.ant.amazon.com>
From: Harald Alvestrand <harald@alvestrand.no>
Openpgp: preference=signencrypt
Autocrypt: addr=harald@alvestrand.no; prefer-encrypt=mutual; keydata= xsFNBFRpbhYBEADXu8uE7LDQgrEB/zclYiwWRb50FnuJjIdK5Q7t68tSxx+LU8HTfxwOgHo9 vMyQvntoRBOHQZDJzvdAnZj/7vtl9RDfWvhUz+o9jSMyORzrt0kiW2QNICVkOkc0ZbI14Rn8 EjFRinK5m5+PXrng3PwZgK+sQJ1nzUxjE9oGTWClsAEqJw62z7JmzNqaEwAyHoHAZ1JAptSP ak91dUxjueJ2R+rFUBl6ParRZ2de7QKr3rN5Jbu/ikjHsAeTSo0R0BPKbzU23tXXxQ/dADvM V/PZp3hRFmXT7x05Q82O6k6hsGd5fJToBDRrlsC3jwWWhDhFhsWcdYKxFbYUsJVetPrWDtD4 6sjrbsQ+7kWRYgQWvL2EJ0s7QGpLxitopoISUEt0MlCcJhq7ZxiWhGnwM3GgADn+9W+aqwuk Y1tlUbdw0qdHyU0WM0k/yPd/eOghk3PLtlOizg4Q22VqfzNRXd3pwUmVjPYHQS0PwIjzuTEI em03qlVeJ8xn0X9W90E8PEnxZmREZBI90qCcUrxWOywEcLq21eLXurRzwnbY3oi6NxmSedcL xDWFdrVTHfPNNqh8zqXV/z9Ezz+7kSwgRygpG5+/sHfFq/YivoSHJdkL8xDzlNiqYCs8EL4A ipQWlKIuFH1F/pXLmXZlcDExw6aTlAP2rR+rw4Lc7kENZlMMMwARAQABzS9IYXJhbGQgQWx2 ZXN0cmFuZCAoMjAxNCkgPGhhcmFsZEBhbHZlc3RyYW5kLm5vPsLBfgQTAQIAKAUCVO3uHAIb IwUJCWYBgAYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQawFW3omifDRKiA/+KtWpGwNa EaMMjxuVhdvMkQ6cS362iWydVbha03TBf/7HM380nO+2/t4S0kiSRtX89bY9lvrjS5oHd0tZ qS14vwBn8ZKbZl+k/NRiFlNNxhBx1PDRni1lfh/lU4xJraKI17h2h9mVJbMGk0kFuLqDUwMc 18mZZcfJEeUxSVUCndFMab4LQWSvRaqcwGrpDXuCxmWzMxtRjZzS2vkNX0oiBO7/NuEdQZL8 /CM3/GTqEd6kqY5Rkddvhr21KqhDyNT0NYRLgQ4yToTRDeXrHkjDD8cIQJhOHSNm6/3tuHB1 Bunxg1If3oEZxZirTGiuNZfBUAuXXJa//wEqhS+28/iQc6RE4bQXh2TyqtHs1mn3VDeKqbp7 lp31FfQ6GVGUaVfKfhg6UPSeczHTKWG3vX5UL7SOLXyaSniuYDkPIV/YR46GFPNhSsQ9YccU 5zAbn8ZhyONwO7524WjhIHgITiPVnCiSIHQKOw0S3+Ns0/5TIUgEc6+M97vsJTxTOqKfPthj xkHckF7VUFzu9ee6IMupJJp1wxVjpPQpJTjUG2aDnWk+E2OArulIjHER2dj0DEiOuqjjwTQH CKfrsWUMIs6TJ9jIKEfOSVOz5opGKLimQaOJ8Y1NYZKOy7fyJjofcC+dkAIpYBRzQTdDXm0A 4eryQBqLSpRldX4rvnU77i2/ryHOwU0EVGluFgEQAK2r1cmzqfJzOIielYx4OGVWlh3TmGdI mPgYI8yx/W8Uyvwknto7Qm5HaBBy9/33usNiovygYLFr7X5U/+ynXClkpAHaPOzS+bMCybpd UsS9Yq/jPmyq0Tlqn6b1tjSjFwysTiUVRS6nHufRlHQEOyxlYAjmePfjJI85g9J3iOa3eY87 +YSlF/rzhPrlvW0yD1YBGBmtuDdRnd4qSof8pcVmiN91QylbnTO5+/VtQtZydk2couaBHkf+ h0eDlJLB7igJ6Ks0ae2UoUNOBv2F1roQ1jZC8yMPScXygmjsoBSuTUirHatyR7AUiCHNymB+ EdhK4Vl+ZVHdCY9l269g5ocw0y6BZofHpqhE9K3RGBWQjWKTXuOk1fVjLfAum3wQqztYEhlD uKZgfEn7reDuzBq4cqzUe7CI6lZwCU7DnA0Dz2vBaqBhrZb7eKfTqmXddNm/dXmPn1nB554N fxWoxb3L8fHXwLgJiBgxLM6OYhJM51PxwW1qoQM1ax6gu+H101uEE4ZZq+s7c301HqwFwGMi SMmn1oJ7/+OquMkYHjeVAhxRE6blcRH2cmqxFSrpHsHgpXMVyWgTZRZsMmQathzCTUWKf5hC EOzwb4rp/UvU1LUHo1uPqbBafW62VB+iUaFp/zOg69Wo8/Z6urM5m+ldiWTbx+ivxKlPQDEA 332dABEBAAHCwWUEGAECAA8FAlRpbhYCGwwFCQlmAYAACgkQawFW3omifDRKhg//eHcjvxcA ENNe66f5R3ULi5pMbrHGLMGirVX9pHTRf5+5OFaGr8bwXeYkCHpptpxr2Kk/PUzpUWOL2uvL lh7QhPw3+GoEWubXOAgHiQW5iIzkA9wYw/nctZ+5veHN7InVqJ7djhtTN7K9Luj4nDR1T7Vf 61zpCKLlEW6W5MAp4slRVzRiFfaMfMYkxLm6MBxC961j8Lrqx2XNMGugaYh1QzcFYTbFmGKX 5SY4EQsETiB0PeE3IBVtXfiabrk8YX2IuL9BrEgD6GngXTd78hUMnZeqjvnS772bjRgwLCz7 Hab6hQESrFCNXfxzb39y5DLHwXtB/HruYqVD48XvPnNV0UNsWcS+7rtPFMmkd3MTvoAOWjkV zeQHpvF71IlwWginXbkf9aR/QsAbMIQDZWhsd+ma67V6g6KH41r6mNXAgK2JlA1CqgblM7iB hl01vL0V5bkbInZq2sB505Hn1DSc4NoP2WHlwe8Bm8vVG5oyfyPw9ReS9WLVY9w7fK4EKOgk VnOsIQuE0WIPT0Ak+hJ0UigOduuCX7s7NIVaOgWQe1q4Xytgj1RHjg9qlA6eQiTUrAx7Mu7s eliWCFuWsQXoaktVEDjoWVbP9dgozanL5kwWh/sJNtHVQbgu3IG4w8D3QvvOE83+jAdzgOzv pqHJkrqlWu+R9ZqBucZLqjQvQZk=
Message-ID: <909be25d-740a-03fd-ecbf-f3fb73f0723d@alvestrand.no>
Date: Mon, 11 Nov 2019 11:59:22 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <20191111090356.mfkn2nbzim7xvhg4@38f9d359441f.ant.amazon.com>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtcweb/iSDGJzQwtSxQwefPn9pw4-C8fsA>
Subject: Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusic-encrypted-ice-candidates
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Nov 2019 10:59:32 -0000
Den 11.11.2019 10:03, skrev Sean DuBois: > On Fri, Nov 01, 2019 at 01:06:22PM -0700, Qingsi Wang wrote: >> Greetings. >> >> This draft ( >> https://tools.ietf.org/html/draft-wang-mmusic-encrypted-ice-candidates-00) >> proposes a complementary solution to the mDNS candidate detailed >> in draft-ietf-rtcweb-mdns-ice-candidates, specifically for managed >> networks. IPs of ICE candidates are encrypted via PSK and signaled as >> pseudo-FQDNs in this proposal, and it aims to address the connectivity >> challenge from the mDNS technique in these managed environments. The >> current work on this draft is tracked in >> https://github.com/tQsW/encrypted-ice-candidates. >> >> Regards, >> Qingsi > >> _______________________________________________ >> rtcweb mailing list >> rtcweb@ietf.org >> https://www.ietf.org/mailman/listinfo/rtcweb > > Hi, > > Really excited to see this RFC. This is a real pain point, and glad it > is being addressed. I implemented this over the weekend and everything > fell into place. > > Have you thought about/explored encrypting the entire SessionDescription? This would destroy interoperability with any currently fielded implementation, so it's unlikely to be popular. It also requires setting up a shared key before you can exchange SDP, which is a pain (as this draft makes clear). > There might be some issues I am not aware of, but it would give us some > other nice things! > > * No more SDP munging (or at least make it harder) > - People shoot themselves in the foot constantly by editing things > - Will push people to communicate API needs more, instead of more hacks > > * Host candidates aren't the only thing you can be fingerprinted off of > - Agents craft very different SDPs (FireFox vs Chromium) > - SDPs reveal hardware attributes (Chromium Android has H264 only with HW Accel) > - Agent may have different experiments/settings (attributes at session/media level) > > * Changes to candidate strings is going to cause more breakage > Maybe this doesn't matter as much, but I anticipate this is going to > cause more bugs. Some clients/SFUs/MCUs... blew up when mDNS came out, > > I bet another change is going to cause the same thing. It sounds like > this will be much less likely because people will need to setup > something up to get the PSK going. > ------- > > I would love to see example implementations of the Key Management. Is > there any precedent for configuration of the WebRTC agent in managed > networks? > > _______________________________________________ > mmusic mailing list > mmusic@ietf.org > https://www.ietf.org/mailman/listinfo/mmusic >
- [rtcweb] [MMUSIC] Draft new: draft-wang-mmusic-en… Qingsi Wang
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Martin Thomson
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Qingsi Wang
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Ted Hardie
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Roman Shpount
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Justin Uberti
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Martin Thomson
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Sean DuBois
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Harald Alvestrand
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Christer Holmberg
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Bernard Aboba
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Roman Shpount
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Iñaki Baz Castillo
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Justin Uberti
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Sean DuBois
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Sean DuBois
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Iñaki Baz Castillo
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Sean DuBois
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Sean DuBois
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Justin Uberti
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Roman Shpount
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Justin Uberti
- Re: [rtcweb] [MMUSIC] Draft new: draft-wang-mmusi… Harald Alvestrand