Re: [rtcweb] Requiring ICE for RTC calls

Matthew Kaufman <matthew.kaufman@skype.net> Tue, 27 September 2011 15:14 UTC

Return-Path: <matthew.kaufman@skype.net>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B90821F8DB6 for <rtcweb@ietfa.amsl.com>; Tue, 27 Sep 2011 08:14:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.413
X-Spam-Level:
X-Spam-Status: No, score=-5.413 tagged_above=-999 required=5 tests=[AWL=1.186, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vitqERX3ycUt for <rtcweb@ietfa.amsl.com>; Tue, 27 Sep 2011 08:14:17 -0700 (PDT)
Received: from mx.skype.net (mx.skype.net [78.141.177.88]) by ietfa.amsl.com (Postfix) with ESMTP id A8BD621F8C6E for <rtcweb@ietf.org>; Tue, 27 Sep 2011 08:14:17 -0700 (PDT)
Received: from mx.skype.net (localhost [127.0.0.1]) by mx.skype.net (Postfix) with ESMTP id 5D1B316F7; Tue, 27 Sep 2011 17:17:02 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=skype.net; h=message-id :date:from:mime-version:to:cc:subject:references:in-reply-to :content-type:content-transfer-encoding; s=mx; bh=wbxpSav+Xj5bh4 wgyYWCXsQ3VLc=; b=WseKctSl0/ELm5PO1jU6YqZoxf4Ms/VCSiRVRHz60cIuRW MdNNDsGN3FjbAQoTEtqsqqUPDfqlsGl6PbPlXlmU8YW9TEVpwF2AmRSd6Q8G8AHV 2ug9ai+XFpIO4j/OSZAtkyMOc6EoZA1AbvxxMlSnn8wDEUicRyZHDics0xK94=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=skype.net; h=message-id:date:from :mime-version:to:cc:subject:references:in-reply-to:content-type: content-transfer-encoding; q=dns; s=mx; b=Q+VLiQ0fLMB34MxA50oCi+ CvOCbuhWFrquS6/BDgJT4C9lkewuXXyh6mDlzXKyED+WGqzE45MBftFCLaweJanP mk4bBQBs0pNaNEUVEOXJEfkhQy6PhItO10pPDwcoP5nCFQutd1YzfmnUsvAPAEUp u8x/Vsqlg4ZkUYpqBVWgA=
Received: from zimbra.skype.net (zimbra.skype.net [78.141.177.82]) by mx.skype.net (Postfix) with ESMTP id 5B08E7F8; Tue, 27 Sep 2011 17:17:02 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1]) by zimbra.skype.net (Postfix) with ESMTP id 3506D1672682; Tue, 27 Sep 2011 17:17:02 +0200 (CEST)
X-Virus-Scanned: amavisd-new at lu2-zimbra.skype.net
Received: from zimbra.skype.net ([127.0.0.1]) by localhost (zimbra.skype.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pPm0OCNQvIQE; Tue, 27 Sep 2011 17:17:01 +0200 (CEST)
Received: from [10.10.155.2] (unknown [198.202.199.254]) by zimbra.skype.net (Postfix) with ESMTPSA id B8D361672683; Tue, 27 Sep 2011 17:17:00 +0200 (CEST)
Message-ID: <4E81E8AB.2080404@skype.net>
Date: Tue, 27 Sep 2011 08:15:55 -0700
From: Matthew Kaufman <matthew.kaufman@skype.net>
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20110902 Thunderbird/6.0.2
MIME-Version: 1.0
To: Roman Shpount <roman@telurix.com>
References: <CAD5OKxtNjmWBz92bRuxka7e-BUpTPgVUvr3ahJGpmZ-U5nuPbQ@mail.gmail.com> <CAD6AjGSmz5T_F+SK2EoBQm6T-iRKp7dd4j8ZAF5JKdbbyomZQA@mail.gmail.com> <CALiegfmO54HC+g9L_DYn4jtXAAbLEvS++qxKa6TNrLDREs9SeA@mail.gmail.com> <4E80984A.903@skype.net> <CALiegfmyvTb57WVooKryS-ubfcg+w5gZ+zfO1zzBLn3609AzaA@mail.gmail.com> <4E809EE6.2050702@skype.net> <CAD5OKxvUOadaU0dnB7-Ho9cZ92VY+4Owuhj7oKPCx9Jy1iwT1Q@mail.gmail.com> <C2DF2C51-B3F7-443D-A047-7E6FB03E6D20@phonefromhere.com> <CAD5OKxsy2eKx5Bc8iayYazSyyykZZTGx9UO7NEE=fxYYdouy0w@mail.gmail.com>
In-Reply-To: <CAD5OKxsy2eKx5Bc8iayYazSyyykZZTGx9UO7NEE=fxYYdouy0w@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Cc: Randell Jesup <randell-ietf@jesup.org>, rtcweb@ietf.org
Subject: Re: [rtcweb] Requiring ICE for RTC calls
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Sep 2011 15:14:18 -0000

On 9/27/2011 7:46 AM, Roman Shpount wrote:
>
> How real or big do you think this problem is going to be? None of the 
> current SIP/VoIP clients address this now, and we have quite a number 
> of them out there. I understand that this is an attack vector but how 
> big of an attack vector is this going to be if we ask for user 
> confirmation?
>

There is no plan to ask for user confirmation to open a connection, 
receive media, or send and receive data. The only user confirmation that 
is expected would be for camera and/or microphone access.

I've seen a dozen messages from you arguing that the requirement for a 
STUN connectivity check is a barrier and should be removed, but I have 
not yet seen an alternative proposal that meets the requirements of 
browser authors with regard to preventing attacks on behind-firewall 
infrastructure from the browser platform.

Matthew Kaufman