Re: [Secdispatch] Introducing MASQUE

David Schinazi <dschinazi.ietf@gmail.com> Tue, 19 March 2019 17:34 UTC

Return-Path: <dschinazi.ietf@gmail.com>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EBF1131571 for <secdispatch@ietfa.amsl.com>; Tue, 19 Mar 2019 10:34:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0U82k3NA4PQc for <secdispatch@ietfa.amsl.com>; Tue, 19 Mar 2019 10:34:14 -0700 (PDT)
Received: from mail-pg1-x536.google.com (mail-pg1-x536.google.com [IPv6:2607:f8b0:4864:20::536]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E3EB131495 for <secdispatch@ietf.org>; Tue, 19 Mar 2019 10:34:14 -0700 (PDT)
Received: by mail-pg1-x536.google.com with SMTP id a22so14296717pgg.13 for <secdispatch@ietf.org>; Tue, 19 Mar 2019 10:34:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=i+5ZBG0gDYw+YR9M0h14tNs5oVal4RBnjh/KXt/h5jU=; b=lTYBPW/K5qez4jKrFbKsKONrTT2hwiitZiBxntNW2ghCTH5aAvWGhrFgjeV677vIt9 Dsq6aivFl+FV1+J0Q3lrhJRM/RZ7+KvSjYOYD+JC+W7YtVCslynsay2dGTEyAYx0ycCu jlZQkuuPXS9cWe9J5rl4HLhOTdt2dgwSocwqsdsX49cSMIcAWEnSKM9IkCCXQroV+Mi+ Sm8Gr8RDZwSBrDSrZVA5DOQrfrAr+QJUs4o0HZ5ugOijSJtCOGh8xAa9uomVFcD+R065 sJkmqn8nYKsKDYpIaN/rDa3p12lJkNWHRk8kGxPX5aQcaD5et+cWQNx79xH7A8fniVDY 2Rhg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=i+5ZBG0gDYw+YR9M0h14tNs5oVal4RBnjh/KXt/h5jU=; b=WiAzyL9n488aJ5o+q07Ma9vAKIRg1Bp8hwsJi56xiOS/Hk5cnOBM7p0kpDrdAYp2BT jNKVtwBcUZkpi8l7Y9sjXAdAOGhxkr2Mijgd5rv0hc1WoXvXsmvBA+q9/WS9jhrDdm9g kSX3L0GZ8x97WSIZQxU1hNB2Ah3WAIVEwcQG3jvOZvAbYcwPC2+xS2+/WVqKDx9VdCog yhqCp1xRiRAGj353VLH7EzUEG9r/3tlZLYB4R+baQrMytbRz5WJNTNxCI+bK/xhNMvaw ICZqdvG1iETpPXLeWqWNh/4ZmtexinONHkSxdmWeznpRkdhlp8FedG1NzUz/tW20yAIc e3Mw==
X-Gm-Message-State: APjAAAW5NyjL4NeiFIldTDvs75asBBHanROUL7fiJx7vqplyz+t2DwX1 k3xcUchxwafJ7onBDyRyFcUMSeryAzDeDbuiLG0=
X-Google-Smtp-Source: APXvYqwNW7GG4tuFDGOFOIjYJ1e3mOEaRFfw/+iY3+r6WDK+Qc7x6uu3OqF0PXtSBnddL/GZXjvgYPWthD4ZSdjCG7M=
X-Received: by 2002:a62:1385:: with SMTP id 5mr1514439pft.221.1553016853488; Tue, 19 Mar 2019 10:34:13 -0700 (PDT)
MIME-Version: 1.0
References: <CAPDSy+4vWgCWU_Vmk=WJj+JTOi0-maB04QY8yWLmemiuYsmGQQ@mail.gmail.com> <CALZ3u+ab0irfBajbxDD7yzx5Cu_aUqtr=n4cRU5MUyg-CNCsag@mail.gmail.com>
In-Reply-To: <CALZ3u+ab0irfBajbxDD7yzx5Cu_aUqtr=n4cRU5MUyg-CNCsag@mail.gmail.com>
From: David Schinazi <dschinazi.ietf@gmail.com>
Date: Tue, 19 Mar 2019 10:34:02 -0700
Message-ID: <CAPDSy+7wbp109KQAo4GQ3o9iVNTGDoighOytkn4rUJZ6nMbkhg@mail.gmail.com>
To: Töma Gavrichenkov <ximaera@gmail.com>
Cc: secdispatch <secdispatch@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000e1e633058475e9f5"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/DrAIHUaAlTshTonfVCdcRENqxx8>
Subject: Re: [Secdispatch] Introducing MASQUE
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Mar 2019 17:34:17 -0000

Thanks Töma. I agree with you - I'll add some text as implementor guidance.

David

On Mon, Mar 18, 2019 at 3:23 PM Töma Gavrichenkov <ximaera@gmail.com> wrote:

> Interesting!
>
> My instant suggestion is to dedicate some effort to allow the performance
> issues of the VPN server to be observed by the HTTP frontend (after
> decryption obviously). Otherwise you may have the same issue we have now
> with Websockets: if a targeted app layer DDoS brings a WS server down, it's
> almost non-traceable in the HTTP access log.
>
> Aiming for that should be complicated but would allow for better DDoS
> resilience, which would be valuable for those individuals hosting HTTP/2-3
> servers you're targeting.
>
> --
> Töma
>