[Secdispatch] Introducing MASQUE

David Schinazi <dschinazi.ietf@gmail.com> Mon, 18 March 2019 19:26 UTC

Return-Path: <dschinazi.ietf@gmail.com>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D647A127961 for <secdispatch@ietfa.amsl.com>; Mon, 18 Mar 2019 12:26:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7X39gEdkkOwW for <secdispatch@ietfa.amsl.com>; Mon, 18 Mar 2019 12:26:42 -0700 (PDT)
Received: from mail-pg1-x52e.google.com (mail-pg1-x52e.google.com [IPv6:2607:f8b0:4864:20::52e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13529129B88 for <secdispatch@ietf.org>; Mon, 18 Mar 2019 12:26:40 -0700 (PDT)
Received: by mail-pg1-x52e.google.com with SMTP id b2so12052781pgl.9 for <secdispatch@ietf.org>; Mon, 18 Mar 2019 12:26:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=YkXuyZiK+KxGpj4TFL4DYJOeCWbcrI42wW17MgjI2cc=; b=Ta1x4Daw4kv/xIlG4wNPjFUE7nTUsyTVIhhm1XFFedqpFqaWPLUkkkJbSkcppUS9Mj CTA/gFyo0NUrClgiaWLYhcAOHZ6//0tUcAdKPkhxBOCj5Vf3Ib6lCFVIJYJsOzOKg8Ty 7I2XI7x6WsbhJ0hiP5725Aj49WfjMO7hWKoW1vv7h9dsFQc8ImRvKrVWPFEComdCZvgT zbfPDNS2NQbHzV0S0eXxlbFmEROYo/vFFYWTxtTzh6y/UFZNi5F0pgL1mrsPkC19+cCQ 3Szjs6BGIAusFQck7MpsXgFxOj2pyevbA/EcrKIkg5xxqnUFGo9ZC+OBfOBgyF7ca6gP FrBg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=YkXuyZiK+KxGpj4TFL4DYJOeCWbcrI42wW17MgjI2cc=; b=VzibSL1h2/YDtHud5mK8XCiUskoH37Io7eccQN2GD8t9dbD0Ua0wYS+p7h59x+YfBb 5YyjHMYQQ8QdEbidCp6YIvCAl5Ztg6nwsjR4h0nbb6nH64/bfRdNxdT8Rh78O358EKmR 5qgLOJyZ4D5zs+XUk6NgrmrBWOjad2hdLN9OidBV1LbPPa/qOTLDSRQDEt6LTLk8urwS HNueiTm2urTlBema8h7+jU1hAUk8mSvJ4C0CElOaZojNMOD+yKk6jOYt9F0NJD3JosUi wbPmcPGV9YHai63yS9tPgLJ73T3f9iZCAtxDLRaVu37yDBanDHcMgWRg1hSUjxyPVkaa HrZA==
X-Gm-Message-State: APjAAAV/sZAX4Q0QgOJZqFjP/7tcU/Pf3q6E12JDuM8ujf9mMeBIeBXg J9E7FfJWrFNkiyYF4M6rY+BPDQN6FFbceYJLszSpzVcG
X-Google-Smtp-Source: APXvYqyfndiK2oLB+GGm4+m94MIaQDUkfmHgAx7kysz74U9dD/JC3Ob/HTmxJ4uS3X1xsXuNAk79NIV+3tChLWZs13M=
X-Received: by 2002:a63:5c60:: with SMTP id n32mr18306044pgm.139.1552937199370; Mon, 18 Mar 2019 12:26:39 -0700 (PDT)
MIME-Version: 1.0
From: David Schinazi <dschinazi.ietf@gmail.com>
Date: Mon, 18 Mar 2019 12:26:28 -0700
Message-ID: <CAPDSy+4vWgCWU_Vmk=WJj+JTOi0-maB04QY8yWLmemiuYsmGQQ@mail.gmail.com>
To: secdispatch <secdispatch@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000208c340584635e5e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/pG11oYDZTtH97iFebtQceXaSfS8>
Subject: [Secdispatch] Introducing MASQUE
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Mar 2019 19:26:44 -0000

Hi secdispatch,

I'd like to share a draft I've recently uploaded:
https://tools.ietf.org/html/draft-schinazi-masque-00

It introduces MASQUE, a protocol for obfuscating a VPN server inside an
HTTP/3 (or HTTP/2) web server. The proposal is pretty new so we'd love to
hear some opinions about how effectively it meets its security goals (or,
alternatively: how poorly it runs its own crypto).

We'll be presenting the draft in Prague - at secdispatch to review the
security aspects and in tsv-area to look into the transport impact.

Thanks,
David