Re: [spring] John Scudder's Discuss on draft-ietf-spring-segment-routing-policy-17: (with DISCUSS and COMMENT)

Robert Raszuk <robert@raszuk.net> Mon, 21 March 2022 23:14 UTC

Return-Path: <robert@raszuk.net>
X-Original-To: spring@ietfa.amsl.com
Delivered-To: spring@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3BF8D3A1364 for <spring@ietfa.amsl.com>; Mon, 21 Mar 2022 16:14:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=raszuk.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BmfQ0ruk8Rpp for <spring@ietfa.amsl.com>; Mon, 21 Mar 2022 16:14:15 -0700 (PDT)
Received: from mail-vk1-xa30.google.com (mail-vk1-xa30.google.com [IPv6:2607:f8b0:4864:20::a30]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 064253A13A5 for <spring@ietf.org>; Mon, 21 Mar 2022 16:14:14 -0700 (PDT)
Received: by mail-vk1-xa30.google.com with SMTP id l184so232065vkh.0 for <spring@ietf.org>; Mon, 21 Mar 2022 16:14:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=raszuk.net; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=3CQfYfTwEgZ/sXnPzj3o85p+z+80VBLQeVQTkkOzwtQ=; b=RYGRxGviaSr7NpgZJiREsERvew2N88F9IFzS2LSA+HGeZRDZ1Pgw/2xJGi7SdaIHIt wIcmOcZJlAf3z7hpdPMN0YwECE9S3+PEF/wlhbzKix9PrjRga2nYqFUf/Xbe8uxJ06xD H5Gy9uePudkMas6hZ55ujVNPfIFKd8e2lCN7S6oU1X85l8ntu23fM9r37tMQc0k1apIy IkgnyL3vj1R9hGIEQEMaZ9KlsLPi+ndr4WVXiUdoLnIx+0nTwazqxpqQs78GEaXJF3Yv GAYCigcQYJoW2PURJ0Ol6NHYKCd1rZh9L8fsQcX25J3YVWdcn9ynIo8YtA2L5MRMdkJZ 9NPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=3CQfYfTwEgZ/sXnPzj3o85p+z+80VBLQeVQTkkOzwtQ=; b=pDN8GiWqsxcnV1ZdQ/MRUNxt+iuhjgTUoDhaX9EXBCkP13Vx8ObsE6+5wFgf1s/YHq o+coevtz/EoGCkgB9wQREyFg2jBEhq46MyNDz+6G/z2R0hQ+hH7CKRX8PNMDYPMuko2q HGjmJcGws3INsdEcdvfuzIi3ulPiz29PhmhBOboK04WgynjErwR65T17K6+XRcwLABEs 5jGlzhhdTySiNrr4y/pSyucQ9NA1Fwm8kPFywrG+/m8+iQ+XT9cpS+KwQwcKKqul6+RR /8JpGBR53eSClz6fDHFtz/WQx00654cFhH6xP91FCxkOftmPK1exsIf+P7mRlqkIIHkD RCcw==
X-Gm-Message-State: AOAM531iWD5rAc/nAC/RLHk0N3yjSTq2o8ewDIQ0kdqKRDmTxM1dBAo/ 8FaJaiHNvo/AEtLhH/pbBKaJ5Rsc2nvc7EzEisHsdQ==
X-Google-Smtp-Source: ABdhPJywNUXhSsVQ1MRkufyudc04BZIrLP9TXCe45QpiSJkCVRMaOtR7e3wQ5b1wN7IjvZDliCd0fO6fvPQoNtaz3V4=
X-Received: by 2002:a05:6122:7c9:b0:33d:d590:585f with SMTP id l9-20020a05612207c900b0033dd590585fmr9199363vkr.18.1647904453373; Mon, 21 Mar 2022 16:14:13 -0700 (PDT)
MIME-Version: 1.0
References: <164503079307.9996.17286143339105134181@ietfa.amsl.com> <CAH6gdPzo+OAoHHQkJD82OdyO=rth8qPPAcco-8STjucnaXNsew@mail.gmail.com> <A7535E25-8DE8-4CBF-9C25-2F12A4692917@juniper.net> <AF504BCF-E8E3-4971-A297-7B3DA1822857@juniper.net>
In-Reply-To: <AF504BCF-E8E3-4971-A297-7B3DA1822857@juniper.net>
From: Robert Raszuk <robert@raszuk.net>
Date: Tue, 22 Mar 2022 00:14:52 +0100
Message-ID: <CAOj+MME=crrWU4vqTpzbGF81Q2fR1XjeQqzMxkfqgAaL5QcLZg@mail.gmail.com>
To: John Scudder <jgs=40juniper.net@dmarc.ietf.org>
Cc: Ketan Talaulikar <ketant.ietf@gmail.com>, "james.n.guichard@futurewei.com" <james.n.guichard@futurewei.com>, "draft-ietf-spring-segment-routing-policy@ietf.org" <draft-ietf-spring-segment-routing-policy@ietf.org>, SPRING WG <spring@ietf.org>, "spring-chairs@ietf.org" <spring-chairs@ietf.org>, The IESG <iesg@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000009144d805dac2a787"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spring/zQ4AdYZmjUPh0JcO40ovLEJtpiE>
Subject: Re: [spring] John Scudder's Discuss on draft-ietf-spring-segment-routing-policy-17: (with DISCUSS and COMMENT)
X-BeenThere: spring@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Source Packet Routing in NetworkinG \(SPRING\)" <spring.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spring>, <mailto:spring-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spring/>
List-Post: <mailto:spring@ietf.org>
List-Help: <mailto:spring-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spring>, <mailto:spring-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Mar 2022 23:14:21 -0000

Hi John,

The point, again, is that by introducing a way for an attacker to cause a
> target system to display arbitrary strings, it would seem reasonable to
> wonder if that creates an opportunity for mischief that doesn’t ordinarily
> exist in our protocols, involving misleading people looking at the
> displayed string in a user interface.
>

Hmmm while I am not clear what "our protocols" mean in this context I do
see a number of cases where protocols have the ability to carry free form
text.

For example, how about RFC8203 ?

There are few other works in progress to also add such ability. So above
all I am trying to sense if your above comment is a specific
to draft-ietf-spring-segment-routing-policy (which is by design *strongly*
limited to the same administration so it would be pretty weird to be
concerned about it) or is it more general in nature ?

Thx,
Robert