Re: [sidr] working group adoption call for draft-kklf-sidr-route-server-rpki-light-01

Warren Kumari <warren@kumari.net> Fri, 06 May 2016 22:33 UTC

Return-Path: <warren@kumari.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 82A5B12D12F for <sidr@ietfa.amsl.com>; Fri, 6 May 2016 15:33:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kumari-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jIez2B4l2LX8 for <sidr@ietfa.amsl.com>; Fri, 6 May 2016 15:33:56 -0700 (PDT)
Received: from mail-qg0-x232.google.com (mail-qg0-x232.google.com [IPv6:2607:f8b0:400d:c04::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A0D1212B01D for <sidr@ietf.org>; Fri, 6 May 2016 15:33:56 -0700 (PDT)
Received: by mail-qg0-x232.google.com with SMTP id f92so63830026qgf.0 for <sidr@ietf.org>; Fri, 06 May 2016 15:33:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kumari-net.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=yulkEym838kIAkJlAz0KwbG2ofElCBgeKEiEsNo0RmQ=; b=n5he+uloD1eh3ToCdixu4Cz3JG5i+bxT9Bc26p+CP9wkiU3Gk7ISsGwKNp4yaf4DL2 y+2wA8B2eZldKXdFnpsrw8EU0s1ELqpEIwQM03AIk+RopvP2jWzDOCBYJ4F5xpupOmd/ bodDGz+uGBsNv2QBP+T0ltShKLKU+ssm5jgTMcQ6UgPuBijGQkl1Xmr06yqUCr5lF8LY Aj058PYUGLsEcQelDGYzEakawus7JrFur4K3BUj/XFc5aJFpOz1HVN6p+RR/4mucmihb 8iG2fkIcJr02heoWYFBHwEdbQbvlMc4r26nfUAaPTywj75hXXJONHe2oc8J1VjOPwBs0 Ufug==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=yulkEym838kIAkJlAz0KwbG2ofElCBgeKEiEsNo0RmQ=; b=V9P2PPIThrxw++6HZGX4j2OpWZkcBQKgsKfE0atIVaBv3LuCZjuZwBdeA5NtoaEYXR uGWzqE8phqyDN4o3Av+FEueXMbEK90ed3qgLOL5mOmFCK8i1m5ic5hdz+W++M/gz451P w+Km2ALVBfocESrWbdHv/DaFRENSgVqFYW52LNUo3+6S2ogXC38s2x1OalLrQTBg158W iGqcsxh4sj/s+hAQch/0NEK5QcgoSsaGDEBRxe8wlmiPSCvP3J9ieuKj8DTlE8BMoxFf 8O7p7umvg/3swHeKqXGTCzdBEYK5Ua9gvaIN8/FeKVwBxmqCi05eWJnEQ7RP6Puvl8N9 ecew==
X-Gm-Message-State: AOPr4FXfNVXgHF5M4ttIR2PenfJpjTTFkqqnYwwTG5bdYAt6sCI71XcsyTYkQiKpPrRJuDIlE8gdOoFZ8pfISljt
X-Received: by 10.140.108.116 with SMTP id i107mr22048789qgf.36.1462574035787; Fri, 06 May 2016 15:33:55 -0700 (PDT)
MIME-Version: 1.0
References: <13075573-8AFA-41D7-B0A3-E2B94DF78E61@tislabs.com> <CAL9jLaa6rcJ42cFyJEW1XTcvMfqnLr++VE7kHgpOG1ywL4S1JA@mail.gmail.com> <alpine.WNT.2.00.1605051758070.2308@mw-PC> <CAL9jLaY355-o1yF+whryMNWTJTyET_d082ZTBapE0CtaVdy3Wg@mail.gmail.com> <22b44efa-bd76-0feb-d1ad-2c5b5c3b845c@gmail.com> <CAL9jLabareh=4_nHMUO2GT8kB94J8yRX3HOJCqU6z3P5iOAPbQ@mail.gmail.com> <CAHw9_iJLZ6T5MQYigEiXcDL21dUkiHT2hezpbq1W8ttet8722A@mail.gmail.com> <m2lh3mlu3x.wl%randy@psg.com>
In-Reply-To: <m2lh3mlu3x.wl%randy@psg.com>
From: Warren Kumari <warren@kumari.net>
Date: Fri, 06 May 2016 22:33:46 +0000
Message-ID: <CAHw9_iJy6Y2KhN922jwfg1bOtfJTR2LKiy+pG5WSzdEHa=JzLQ@mail.gmail.com>
To: Randy Bush <randy@psg.com>
Content-Type: multipart/alternative; boundary="001a113aadc2dc7fc20532340db7"
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/R4AZ-VUf_8opPXBUCjaAt3JUeoQ>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] working group adoption call for draft-kklf-sidr-route-server-rpki-light-01
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 May 2016 22:33:58 -0000

On Fri, May 6, 2016 at 6:06 PM Randy Bush <randy@psg.com> wrote:

> > Some people do use route servers, and won't do their own validation -
> > I'd rather that they have the information available to make a decision
> > than not...
>
> this glibly glosses over that, by outsourcing origin validation, an
> attack vector is introduced.


Yup.


> i presume i do not need to describe it.
> so it needs to be big in the sec cons.
>

Yup, I fully agree. I had a flag set to mention that, but somehow lost it.
It definitely needs to be stressed -- you really really really should do
your own validation. If, for some reason you cannot / will not, having
someone else doing your validation *might* be better than nothing, but it
also might not be...

W

>
> randy
>