Re: [rtcweb] Security implications of host candidates

youenn fablet <youennf@gmail.com> Thu, 12 July 2018 15:21 UTC

Return-Path: <youennf@gmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF6D7130E78 for <rtcweb@ietfa.amsl.com>; Thu, 12 Jul 2018 08:21:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W7YIT7AnrCiN for <rtcweb@ietfa.amsl.com>; Thu, 12 Jul 2018 08:21:31 -0700 (PDT)
Received: from mail-lj1-x236.google.com (mail-lj1-x236.google.com [IPv6:2a00:1450:4864:20::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 113AD130E5F for <rtcweb@ietf.org>; Thu, 12 Jul 2018 08:21:30 -0700 (PDT)
Received: by mail-lj1-x236.google.com with SMTP id q127-v6so21680237ljq.11 for <rtcweb@ietf.org>; Thu, 12 Jul 2018 08:21:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=J+ADCtm4TJHjBDTsBOoDkr/6QyMFQFg8fiRy/gqrXG8=; b=O/gxPlWL8QYU2DzzhRzjuLgzOvEvzq0AM9vlOnIgtUoSqkFIczziP3AHMs4wOnOx4u 6MRkCrjccQAoy1gV9UmSkWJHOBBtxhi+y5mUwdcYek+lv0plFpZL7Te8LuMfHEbMwchL 7ZvodVBexKMKK/TwDduV4PEN+cikShBCuVD991TXlt/fjlcCMwKiJ1p/M7HtlzHj9DjC XsdIW+Q83Jw+SvlpCPeRUGuFEoSF1b4upeOB+qKWDaEYFNK2rmuKrd+K6nsE3INm0Rjh 96yej2kx6ldTFTOwg3YJsZdlviRDaVqr5IvTsvbIKZldt4Vp8jSde6k6Q0frmHT0XwH9 KuBg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=J+ADCtm4TJHjBDTsBOoDkr/6QyMFQFg8fiRy/gqrXG8=; b=Pox8RYF12rNwifph72qdzVMpKrIZSS7w4cUJgggh/OXEVMvxHi7zLFki7mme2ppN5R khhRIJrYpjJMFXYq6qbBrJDW6BaNdXivxVHlYcMCrn5FT+TgNr8H9KZMUeeahCL1Fo+F vhZyGM2X97kG3V3k2RRTVYG8VErpjnQrUErIStqOYPUm2iJWNdmjQlk0doHfTKxfk220 hKWD78VohJ844rwrJ74wJwlII/3Ud1HlE+JEzzRdTmOf1d65hzoZhkrZSl4vX+6cHCJP kwudXExw8zoROGe9Os2TDNFkmPMIFCdef/sOTuZXhjkqkg+ctqaRoRrG6u1Z7UdZKmy8 kE/w==
X-Gm-Message-State: AOUpUlG4IXjDBbREdEkH2XB8jF3clZVVltz+IjTdjMDhCAG7+bEjRwJ+ BLxeRZGoMz7pyeGKADJJ9StDtjJfJcm+9AR4nvQ=
X-Google-Smtp-Source: AAOMgpd8C+Gehjq92KB32zua6S2t/lEmgHwpBEtG3yPCyWJSvtqqk55k41jotNTo5wEwLYoKJabxTEe0rotQRx5qrgE=
X-Received: by 2002:a2e:6d11:: with SMTP id i17-v6mr888440ljc.116.1531408888182; Thu, 12 Jul 2018 08:21:28 -0700 (PDT)
MIME-Version: 1.0
References: <CAOJ7v-1t_BDEEHmA4eqiS9ksYOOyHUz9LFLhQxs8FhjTdswP5w@mail.gmail.com> <CAOJ7v-3X2Sj8Yid+i0=xadyH_Hmf4pMOF_iuOV+56Ty8HNnJuw@mail.gmail.com> <0ED74BE5-AC02-44C5-80E1-18532BD3D1FF@westhawk.co.uk> <CAOJ7v-0TGqvp=MUmeEUjYZTcvV37qbYSTV0pFMoi1J0CJQ7Q4A@mail.gmail.com> <CABkgnnXBTC5TERquJPO4dgiAKz037Cm0Omw4YrobtCW=wmGPyQ@mail.gmail.com> <CAOJ7v-0yzvu9POvR4Auokykqc63eju6_CveAzyVpcSd1kkK6Nw@mail.gmail.com> <CABkgnnXL6sdCDt=hjX+7KbP+xYm9jCmgjJNy4CvPPna_0oin=g@mail.gmail.com> <CAOJ7v-33ODGTsmbHEp_U7UdROvuKR7O7bne2_0tX6ivVf-+C5A@mail.gmail.com> <CABkgnnWJM4CE2ZLHYOOd=VYUj7kn5wFMAbeGB1HRyp++nvbPoQ@mail.gmail.com> <CAOJ7v-2WGyHSbSJwgbVVHLs-GO71rMLS2+OTetNyMhb0TM3ZcA@mail.gmail.com> <54EB6378-5DA2-4125-A4F4-84151D0E4F04@apple.com> <CAOJ7v-2dw1coDTpovTrKa__Oak7Jjn5EYgvWtByaRYmxfDDtXw@mail.gmail.com> <1d60feec-3a36-2deb-e4a7-703fb7144ed1@alvestrand.no> <68bb5744-d9f2-462c-446d-ae47f2f27e5e@gmail.com> <CAOJ7v-3CF5hXxOGkufzdP6VqrvjHW6BhnB1mjVnHjwv8pcP7KA@mail.gmail.com> <c5ec2bed-b3f6-ece6-e5f1-698690f2d115@alvestrand.no>
In-Reply-To: <c5ec2bed-b3f6-ece6-e5f1-698690f2d115@alvestrand.no>
From: youenn fablet <youennf@gmail.com>
Date: Thu, 12 Jul 2018 08:21:16 -0700
Message-ID: <CANN+akYJTw8w8iMS0pvkkWUoLyUCS5yGqemVYgm-bYSXZohm=Q@mail.gmail.com>
To: Harald Alvestrand <harald@alvestrand.no>
Cc: rtcweb@ietf.org
Content-Type: multipart/alternative; boundary="000000000000c93d620570ceeaf9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtcweb/xx3MFX99Dgt-Cvb0wCEcU3idQ1E>
Subject: Re: [rtcweb] Security implications of host candidates
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Jul 2018 15:21:33 -0000

> I must be missing something - if both endpoints hide public v4/v6
> addresses using mdns (whether they are host addresses or learned via
> STUN), we preclude communication outside the local mDNS domain.
>

I do not think addresses learned via STUN are to be hidden, they are
already known from any web site.