Re: [Sip] Thoughts on SIP Identity issues

Hadriel Kaplan <HKaplan@acmepacket.com> Fri, 01 August 2008 00:55 UTC

Return-Path: <sip-bounces@ietf.org>
X-Original-To: sip-archive@optimus.ietf.org
Delivered-To: ietfarch-sip-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id ED8F428C310; Thu, 31 Jul 2008 17:55:32 -0700 (PDT)
X-Original-To: sip@core3.amsl.com
Delivered-To: sip@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0761128C28A for <sip@core3.amsl.com>; Thu, 31 Jul 2008 17:55:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OOFo6YFdE8QV for <sip@core3.amsl.com>; Thu, 31 Jul 2008 17:55:24 -0700 (PDT)
Received: from etmail.acmepacket.com (etmail.acmepacket.com [216.41.24.6]) by core3.amsl.com (Postfix) with ESMTP id D1D9B3A6A03 for <sip@ietf.org>; Thu, 31 Jul 2008 17:55:23 -0700 (PDT)
Received: from mail.acmepacket.com (216.41.24.7) by etmail.acmepacket.com (216.41.24.6) with Microsoft SMTP Server (TLS) id 8.1.291.1; Thu, 31 Jul 2008 20:54:43 -0400
Received: from mail.acmepacket.com ([216.41.24.7]) by mail.acmepacket.com ([216.41.24.7]) with mapi; Thu, 31 Jul 2008 20:54:43 -0400
From: Hadriel Kaplan <HKaplan@acmepacket.com>
To: Eric Rescorla <ekr@networkresonance.com>
Date: Thu, 31 Jul 2008 20:54:43 -0400
Thread-Topic: [Sip] Thoughts on SIP Identity issues
Thread-Index: AcjzTzgUuwAS6LhhQE67ZyFCgTFT5gABTz6A
Message-ID: <E6C2E8958BA59A4FB960963D475F7AC30F04C5632F@mail.acmepacket.com>
References: <0D5F89FAC29E2C41B98A6A762007F5D0F266CD@GBNTHT12009MSX.gb002.siemens.net> <02829328-7B0E-41AB-B325-01246363D09C@cisco.com> <4DAE5E60BA49D8419D7C8832503F5FFC072817AF26@EVS10.ams.gblxint.com> <0D5F89FAC29E2C41B98A6A762007F5D0F26CCB@GBNTHT12009MSX.gb002.siemens.net> <48919248.7060600@cisco.com> <0ae201c8f310$d183a0f0$3675150a@cisco.com> <E6C2E8958BA59A4FB960963D475F7AC30F04C561DB@mail.acmepacket.com> <20080731205152.03E7E514892@kilo.rtfm.com>
In-Reply-To: <20080731205152.03E7E514892@kilo.rtfm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
MIME-Version: 1.0
Cc: 'Cullen Jennings' <fluffy@cisco.com>, "'Uzelac, Adam'" <Adam.Uzelac@globalcrossing.com>, 'SIP IETF' <sip@ietf.org>, "'Elwell, John'" <john.elwell@siemens.com>, Dan Wing <dwing@cisco.com>
Subject: Re: [Sip] Thoughts on SIP Identity issues
X-BeenThere: sip@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Session Initiation Protocol <sip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sip>, <mailto:sip-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:sip@ietf.org>
List-Help: <mailto:sip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sip>, <mailto:sip-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: sip-bounces@ietf.org
Errors-To: sip-bounces@ietf.org


> -----Original Message-----
> From: Eric Rescorla [mailto:ekr@networkresonance.com]
>
> Funny you should mention that.
>
> It's becoming increasingly clear that VBR codecs leak a fair
> amount of information, even when they are encrypted [WBC+08].
> So, if, for instance, you were planning to use a fixed-rate
> codec and an attacker could force you into a VBR codec, that
> might leak information.

Fascinating paper. (truly)  But it sounds more like just a reason to fix SRTP for VBR, through random padding or whatever.

-hadriel
_______________________________________________
Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sipping@ietf.org for new developments on the application of sip