Re: [sidr] working group adoption call for draft-kklf-sidr-route-server-rpki-light-01

Randy Bush <randy@psg.com> Fri, 06 May 2016 22:32 UTC

Return-Path: <randy@psg.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 361E512D12F for <sidr@ietfa.amsl.com>; Fri, 6 May 2016 15:32:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.896
X-Spam-Level:
X-Spam-Status: No, score=-7.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.996] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vklTHflnt6UC for <sidr@ietfa.amsl.com>; Fri, 6 May 2016 15:32:16 -0700 (PDT)
Received: from ran.psg.com (ran.psg.com [IPv6:2001:418:8006::18]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1443F12D0C0 for <sidr@ietf.org>; Fri, 6 May 2016 15:32:16 -0700 (PDT)
Received: from localhost ([127.0.0.1] helo=ryuu.psg.com) by ran.psg.com with esmtp (Exim 4.82) (envelope-from <randy@psg.com>) id 1ayoIA-0005Zf-Jo; Fri, 06 May 2016 22:32:15 +0000
Date: Sat, 07 May 2016 07:32:13 +0900
Message-ID: <m2k2j6lswi.wl%randy@psg.com>
From: Randy Bush <randy@psg.com>
To: Aris Lambrianidis <aristidis.lambrianidis@ams-ix.net>
In-Reply-To: <572D1A7E.9020208@ams-ix.net>
References: <13075573-8AFA-41D7-B0A3-E2B94DF78E61@tislabs.com> <CAL9jLaa6rcJ42cFyJEW1XTcvMfqnLr++VE7kHgpOG1ywL4S1JA@mail.gmail.com> <alpine.WNT.2.00.1605051758070.2308@mw-PC> <CAL9jLaY355-o1yF+whryMNWTJTyET_d082ZTBapE0CtaVdy3Wg@mail.gmail.com> <22b44efa-bd76-0feb-d1ad-2c5b5c3b845c@gmail.com> <CAL9jLabareh=4_nHMUO2GT8kB94J8yRX3HOJCqU6z3P5iOAPbQ@mail.gmail.com> <CAHw9_iJLZ6T5MQYigEiXcDL21dUkiHT2hezpbq1W8ttet8722A@mail.gmail.com> <m2lh3mlu3x.wl%randy@psg.com> <572D1A7E.9020208@ams-ix.net>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.7 - "Harue")
Content-Type: text/plain; charset="US-ASCII"
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/4rXlLjCErRkgL6fZhYHM6zRWNt4>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] working group adoption call for draft-kklf-sidr-route-server-rpki-light-01
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 May 2016 22:32:17 -0000

>> this glibly glosses over that, by outsourcing origin validation, an
>> attack vector is introduced.  i presume i do not need to describe it.
>> so it needs to be big in the sec cons.
> Is it bigger than the attack vector allowed for when not doing origin 
> validation at all?

now we're comparing the size of the guns used to shoot yourself in the
foot?

my point was that it needs to go in the sec cons.  not the size of the
type to be used.

randy