Re: [T2TRG] QUIC on IoT boards

"Eliot Lear (elear)" <elear@cisco.com> Mon, 20 January 2020 13:45 UTC

Return-Path: <elear@cisco.com>
X-Original-To: t2trg@ietfa.amsl.com
Delivered-To: t2trg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2060D120125 for <t2trg@ietfa.amsl.com>; Mon, 20 Jan 2020 05:45:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Level:
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=YBW6CMTN; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=jslMmbAb
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FIyokeREAGts for <t2trg@ietfa.amsl.com>; Mon, 20 Jan 2020 05:45:32 -0800 (PST)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F89A120120 for <t2trg@irtf.org>; Mon, 20 Jan 2020 05:45:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1434; q=dns/txt; s=iport; t=1579527932; x=1580737532; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=kLOJZrsClthMH3P7K0R5zh+0LkuynKsD/3fRawsFMuE=; b=YBW6CMTNCLlbfzl0ZYwVl4NFGNwr/28q5kQ9dmvASnAL1YUwK1KabAfg gq/eUxK85n8XBObObjmgf6+a6oFIGd9Cfk5gKbKspYoDJPwNL1I3zvedq xd+qzI0crP0oHiFTVXF2gE/zgRywgkVVz6bS8+1Hexk6CDpWEY/Jcpigl E=;
IronPort-PHdr: 9a23:iFP8JRy7+Q+ehdXXCy+N+z0EezQntrPoPwUc9psgjfdUf7+++4j5YRyN/u1j2VnOW4iTq+lJjebbqejBYSQB+t7A1RJKa5lQT1kAgMQSkRYnBZuIDUDyNtbhbjcxG4JJU1o2t3w=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CnAACtriVe/4gNJK1lHAEBAQEBBwEBEQEEBAEBgWkFAQELAYFTUAVsWCAECyqEEoNGA4p8gl+YDoEugSQDVAkBAQEMAQEjCgIBAYRAAheBeCQ2Bw4CAw0BAQQBAQECAQUEbYU3DIVeAQEBAQEBARIREQwBATcBBAsCAQgYAgImAgICMBUQAgQOBSKDBAGCSgMOIAEOoFcCgTmIYXWBMoJ/AQEFgS8BgRSCQBiCDAMGgQ4qAYwTGoFBP4ERJyCCTD6CZAOEcjKCLJBVngt2CoI5hz2OdBQHmneXP5IlAgQCBAUCDgEBBYFZAy+BWHAVZQGCQVAYDYgBDBeDUIUUhT90gSmMSwEB
X-IronPort-AV: E=Sophos;i="5.70,342,1574121600"; d="scan'208";a="421543523"
Received: from alln-core-3.cisco.com ([173.36.13.136]) by alln-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 20 Jan 2020 13:45:14 +0000
Received: from XCH-RCD-004.cisco.com (xch-rcd-004.cisco.com [173.37.102.14]) by alln-core-3.cisco.com (8.15.2/8.15.2) with ESMTPS id 00KDjE2x030107 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 20 Jan 2020 13:45:14 GMT
Received: from xhs-rcd-001.cisco.com (173.37.227.246) by XCH-RCD-004.cisco.com (173.37.102.14) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 20 Jan 2020 07:45:14 -0600
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by xhs-rcd-001.cisco.com (173.37.227.246) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 20 Jan 2020 07:45:13 -0600
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Mon, 20 Jan 2020 07:45:13 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=J9Vs2L4VspNOiN6nacNukUM/DK8rOtC9zlnYFD4fOqc7v+Ehk8IIlQ9+GE41MkjqEMXbTJD9o5fPNZw5EjN0T3CzDNQDFnZKXRirSkA8fJsZaGcdMWApXQKjzGd0pqNrL9cO731CEhSlBzmpHuhpCEWnDryy63Tpb9TyBeyyqpaKTJpXNBoKT4ZkrqRq+nA7mGw0ttr0FXXxV3/Ag853H9ScT6Y8FsUZZiD1dPGtSOYICp0Z6jb8cNSl8vKbPC3a5zShcPOebV8mAfQOxzsEab1TGsZ5dbA0oclIsjSIYKOesPwOjyBqOlnlNHF7MGGE6HqzQ4u/wiWXwRjrcYZirQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kLOJZrsClthMH3P7K0R5zh+0LkuynKsD/3fRawsFMuE=; b=oWmIZUUgPAhF2Qwo7cgnFyy8PsIpB3BjEt5k+ZfuiVqwsuNVPFdMW/FhiB417zTBHTbQixOL6ttVCAqKR5hSE8MBr+QWnZ4bQktDMUDFPO+VOfljyscehp6Fjef6buJ2IbJNZD8kfl+dtRpl1SeTG70YyLujuz0GZUi2aiy2YGRKeYixuq1XpQiFhPUN5PhnK+ud5NUvKYsuYLd5Wuc5b+ihcIiKzXcJQVMeFlPwabCgZ9Z27aP/yZV0Ra/tNlHYML1DMAXifVOHO1mrO2VqDAiyi+ZnChZNvaE4v/H9+CI6vm05pvFqhSn/g/LyX59d/loqucpwKcCDzWG2lDJCbg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kLOJZrsClthMH3P7K0R5zh+0LkuynKsD/3fRawsFMuE=; b=jslMmbAbusbGdRkq3SaiN0vZLFJsgci0p9r1PP9oHnDrQmuoQTaXXgnW2V65LQIqAw+kHnyFjCu9M/n8iPfMFPhzxBreU3QGPkc8dZZYJOI5zSWBeTcrs7+yYQZV5oXozMsGaM65wBMrN0mPSEvKjEYlZGaJCurylHHya8oGBTc=
Received: from DM6PR11MB3995.namprd11.prod.outlook.com (10.255.61.204) by DM6PR11MB4027.namprd11.prod.outlook.com (20.176.126.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2644.23; Mon, 20 Jan 2020 13:45:11 +0000
Received: from DM6PR11MB3995.namprd11.prod.outlook.com ([fe80::594a:23a:5e3:34e5]) by DM6PR11MB3995.namprd11.prod.outlook.com ([fe80::594a:23a:5e3:34e5%7]) with mapi id 15.20.2644.026; Mon, 20 Jan 2020 13:45:11 +0000
From: "Eliot Lear (elear)" <elear@cisco.com>
To: Lars Eggert <lars@eggert.org>
CC: "lwip@ietf.org" <lwip@ietf.org>, "t2trg@irtf.org" <t2trg@irtf.org>
Thread-Topic: [T2TRG] QUIC on IoT boards
Thread-Index: AQHVz2skm4uQ7wgpi0GXpG9UCNFJCafzkNMA
Date: Mon, 20 Jan 2020 13:45:11 +0000
Message-ID: <E7C38177-DD0B-4D92-AE0E-EB457691E493@cisco.com>
References: <6CB4D459-4AAA-4313-B95C-05DF22C9A9DD@eggert.org>
In-Reply-To: <6CB4D459-4AAA-4313-B95C-05DF22C9A9DD@eggert.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=elear@cisco.com;
x-originating-ip: [2001:420:c0c0:1003::6]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 76942f42-a0f9-43cf-5cf6-08d79daef898
x-ms-traffictypediagnostic: DM6PR11MB4027:
x-microsoft-antispam-prvs: <DM6PR11MB40279EEC9CDD73122C2E29F1BF320@DM6PR11MB4027.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0288CD37D9
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(136003)(396003)(376002)(346002)(39860400002)(366004)(199004)(189003)(66556008)(66446008)(64756008)(6486002)(66946007)(66476007)(186003)(6512007)(33656002)(8936002)(36756003)(71200400001)(2616005)(91956017)(76116006)(6916009)(4326008)(5660300002)(54906003)(81166006)(81156014)(966005)(316002)(4744005)(478600001)(2906002)(66574012)(6506007)(86362001)(8676002)(53546011); DIR:OUT; SFP:1101; SCL:1; SRVR:DM6PR11MB4027; H:DM6PR11MB3995.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Bz+AnI4t2LV7x2hWaSffyGgLDw4eAJKgTdGsQfVrrkX+OmCSprqtq5jdG1GtyC9cxJ+vKHetAVNWSfuywVIhU0yJbaeZgfwALiVOrS/Dcj8U3KQKLusTzEIXoDV/JZCizKZm4s0mN8u7Cegn1R7/SF58Mn+wnzNRxJhxJxmd9Zqi2JHt3vMiGC4M1GoLTHl9aiaegnek+7ufmgOMWg6lvRoq4qSju8e95JV0/Grr4IBfm4gCOyt7sZ4cPmKwqc3ATCbs65/7Nd7khWvoBNQUJ6d1xPsnSwcNXjptTHS7QSyt2T38xkzVV28PlbY7OunBuHyDmVK5Zd+yZpwcSSilqN++LY69RVyfz2FWrvGTb/X+jahjsjcWSlcLM7M16+oN4ebEx8NcshlImXEcbRO/8FbdULi8xAi1xRXYIEqoSfwp6qMDf8h5HJ3qC53U34RluSFtKOiBqB8FhRxTNHXcolMrDyJ+XGpjdrLrOsn5Jlp5zIQ23GuIuc6Yci+JEaIHWCtD2BCy0MrlMW2fz+cXJQ==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <F63EF7A27467B840BB74E21FB1C30326@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 76942f42-a0f9-43cf-5cf6-08d79daef898
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Jan 2020 13:45:11.4641 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 5p8N1n5Dom3SRwxeiQB9kjUFagvk15BHV6Xh4A1sKA1+ibdNAI28flznVujleRCw
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR11MB4027
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.14, xch-rcd-004.cisco.com
X-Outbound-Node: alln-core-3.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/t2trg/kBVeqQoNBlh3JCRSJJlfOCjQd-w>
Subject: Re: [T2TRG] QUIC on IoT boards
X-BeenThere: t2trg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IRTF Thing-to-Thing Research Group <t2trg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/t2trg>, <mailto:t2trg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/t2trg/>
List-Post: <mailto:t2trg@irtf.org>
List-Help: <mailto:t2trg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/t2trg>, <mailto:t2trg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Jan 2020 13:45:38 -0000

Hi Lars,

A fundamental question to ask is whether which IoT uses QUIC is appropriate for and which ones it is not.  For example, obscuring port information on an industrial device – not to mention encrypting communications – might actually cause more harm than good if the result is an inability to audit industrial automation behavior.  As in: why did that signal turn green that caused two trains to collide?

Be careful what you wish for.  You may not like the results.

Eliot

> On 20 Jan 2020, at 09:24, Lars Eggert <lars@eggert.org> wrote:
> 
> Signed PGP part
> Hi,
> 
> I wrote up my experiences of getting QUIC to run on some IoT boards for the NDSS DISS workshop. Feedback welcome!
> 
> Towards Securing the Internet of Things with QUIC. Lars Eggert. Proc. NDSS Workshop on Decentralized IoT Systems and Security (DISS), San Diego, CA, USA, February 23, 2020. https://eggert.org/papers/2020-ndss-quic-iot.pdf
> 
> Would be happy to chat about this more, possibly in Vancouver?
> 
> Thanks,
> Lars
> 
> 
>