Re: [secdir] Secdir review of draft-murchison-nntp-compress-05

Alexey Melnikov <alexey.melnikov@isode.com> Mon, 21 November 2016 17:25 UTC

Return-Path: <alexey.melnikov@isode.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6907312957A; Mon, 21 Nov 2016 09:25:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.599
X-Spam-Level:
X-Spam-Status: No, score=-1.599 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-1.497, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isode.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TADprHu9bkmz; Mon, 21 Nov 2016 09:25:53 -0800 (PST)
Received: from statler.isode.com (Statler.isode.com [62.232.206.189]) by ietfa.amsl.com (Postfix) with ESMTP id 604BB12956D; Mon, 21 Nov 2016 09:25:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1479749152; d=isode.com; s=june2016; i=@isode.com; bh=TawXVUsyf0kmlwxoSV7qhkIvErvFZHAh8E55+nNup+A=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=Rp8PJ2+6Axi+eGS+4aWAFXVzWIBmrN0mVbKFkfDsmeiO+FUtjSoRQZEgQKSmwz5vaXI42o 3ADCJH36BruJ3Hj3wWOr+As5Q2Qe0uEmuepvbzp8gbfu9lfoI7jMiS3EVFiobhJczvArhX yHvrcP75k+yKfMjjRR8y76DXnDxF2gU=;
Received: from [172.20.1.215] (dhcp-215.isode.net [172.20.1.215]) by statler.isode.com (submission channel) via TCP with ESMTPSA id <WDMuHwAY16km@statler.isode.com>; Mon, 21 Nov 2016 17:25:52 +0000
To: =?UTF-8?Q?Julien_=c3=89LIE?= <julien@trigofacile.com>, Barry Leiba <barryleiba@computer.org>
References: <CALaySJ+mJdorTkygsZ==Bja+0ZmavTkq2kC33QJ67LeM34K=Ng@mail.gmail.com> <20981db3190142193043f1445abadaa3@trigofacile.com> <CALaySJKP3AEgb7=rRz=T0R4vKWOHE6AAHeg-k-h28KrtjXP64A@mail.gmail.com> <bf55ee7b-13ae-a162-ceb7-57ccedac1d35@trigofacile.com> <1b5edd03-675c-01b7-6d06-c2e155987929@trigofacile.com>
From: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <fa6925d7-ed59-fa47-c4c0-14f514492f53@isode.com>
Date: Mon, 21 Nov 2016 17:25:48 +0000
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
In-Reply-To: <1b5edd03-675c-01b7-6d06-c2e155987929@trigofacile.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-transfer-encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/qSNuxjxLjYMLW3kyudR9ussFmXM>
Cc: draft-murchison-nntp-compress.all@ietf.org, IESG <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] Secdir review of draft-murchison-nntp-compress-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Nov 2016 17:25:54 -0000

Hi Julien,

Sorry for the late followup on this.

On 03/10/2016 21:47, Julien ÉLIE wrote:

> Hi Barry,
>
> I'm currently reviewing the comments I need to take into account for 
> the document.
> Do you believe I should add a note about a possible security issue as 
> far as the use of DEFLATE is concerned?  (see below)
> (An "out of memory" attack?)

I think this would be a good idea.

Best Regards,
Alexey