Re: [Tigress] post-118 direction

Yogesh Karandikar <ykarandikar@apple.com> Thu, 30 November 2023 20:28 UTC

Return-Path: <ykarandikar@apple.com>
X-Original-To: tigress@ietfa.amsl.com
Delivered-To: tigress@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6614BC14F75F for <tigress@ietfa.amsl.com>; Thu, 30 Nov 2023 12:28:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w9CE4dyeMcM7 for <tigress@ietfa.amsl.com>; Thu, 30 Nov 2023 12:28:09 -0800 (PST)
Received: from rn-mailsvcp-mx-lapp02.apple.com (rn-mailsvcp-mx-lapp02.apple.com [17.179.253.23]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 99715C14EB19 for <tigress@ietf.org>; Thu, 30 Nov 2023 12:28:09 -0800 (PST)
Received: from rn-mailsvcp-mta-lapp03.rno.apple.com (rn-mailsvcp-mta-lapp03.rno.apple.com [10.225.203.151]) by rn-mailsvcp-mx-lapp02.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPS id <0S4Y0053OE6O0V20@rn-mailsvcp-mx-lapp02.rno.apple.com> for tigress@ietf.org; Thu, 30 Nov 2023 12:28:09 -0800 (PST)
X-Proofpoint-GUID: CE-a8_0ufW0pTuEuhioOtuW94CLovfBU
X-Proofpoint-ORIG-GUID: CE-a8_0ufW0pTuEuhioOtuW94CLovfBU
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.619, 18.0.997 definitions=2023-11-30_20:2023-11-30, 2023-11-30 signatures=0
X-Proofpoint-Spam-Details: rule=interactive_user_notspam policy=interactive_user score=0 malwarescore=0 adultscore=0 phishscore=0 suspectscore=0 mlxscore=0 spamscore=0 mlxlogscore=999 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2311060000 definitions=main-2311300150
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apple.com; h=from : message-id : content-type : mime-version : subject : date : in-reply-to : cc : to : references; s=20180706; bh=EpMKRuxgSPGKr6Xx8AKllk1XbcQhv163Gup9MrtuvOA=; b=GcX+bqfy2mMJlLoHLsw9SnEoKgg8rNbJlI/5gvuPT7SMT+NwbRbh0OUB0UBagHu7MXk4 BpWhWWS0lPzVWZoCDu7zQgqExWftmvU+bcqa03v3dnQnwXtqHL0xCqNtpn3ipVCpmT+y /Xi9qPeYcicejACbw0yD74D1yzNMszcbF16VCLN6kTBDOp02mbCkgu3bdwAvw8mIEVQa FfNOj2DWGu6qjrSft6jUROL7krBWi9PmP4Cd1F7C7XHwEoVv8YVA7yaZvWW5I5W8x7wL YLC9cDsOwUYq8YuFIRPjUAv0vJgkbWLUwi769T8C5oW5/Ak49wgaZZzctLRKOxLrhyU9 tw==
Received: from rn-mailsvcp-mmp-lapp02.rno.apple.com (rn-mailsvcp-mmp-lapp02.rno.apple.com [17.179.253.15]) by rn-mailsvcp-mta-lapp03.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPS id <0S4Y010QYE6U0IV0@rn-mailsvcp-mta-lapp03.rno.apple.com>; Thu, 30 Nov 2023 12:28:06 -0800 (PST)
Received: from process_milters-daemon.rn-mailsvcp-mmp-lapp02.rno.apple.com by rn-mailsvcp-mmp-lapp02.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) id <0S4Y00000DSCDM00@rn-mailsvcp-mmp-lapp02.rno.apple.com>; Thu, 30 Nov 2023 12:28:06 -0800 (PST)
X-Va-A:
X-Va-T-CD: 7305fa71fb16944fd59017088e4bb394
X-Va-E-CD: 60e4ac9ef907b233e025adc6af3950b8
X-Va-R-CD: 64f3965d4ce02af6bc89898784174812
X-Va-ID: dfb750de-2748-49a5-afc1-ec5f5a98a413
X-Va-CD: 0
X-V-A:
X-V-T-CD: 7305fa71fb16944fd59017088e4bb394
X-V-E-CD: 60e4ac9ef907b233e025adc6af3950b8
X-V-R-CD: 64f3965d4ce02af6bc89898784174812
X-V-ID: 39b3ecf0-1fb1-4895-a9cc-34051060d9c8
X-V-CD: 0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.619, 18.0.997 definitions=2023-11-30_20:2023-11-30, 2023-11-30 signatures=0
Received: from smtpclient.apple (unknown [17.194.82.202]) by rn-mailsvcp-mmp-lapp02.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPSA id <0S4Y00E6GE6UG900@rn-mailsvcp-mmp-lapp02.rno.apple.com>; Thu, 30 Nov 2023 12:28:06 -0800 (PST)
From: Yogesh Karandikar <ykarandikar@apple.com>
Message-id: <925ABEC2-DACD-4BB9-AB96-B42B4042302F@apple.com>
Content-type: multipart/alternative; boundary="Apple-Mail=_3A829DD3-FCF8-4515-9835-69A33962055B"
MIME-version: 1.0 (Mac OS X Mail 16.0 \(3774.300.61.1.2\))
Date: Thu, 30 Nov 2023 12:27:56 -0800
In-reply-to: <CAA1-vB2a1kX916rCixqP-VD7NLUu7zR5j0YX=saHwmDXyZXbjA@mail.gmail.com>
Cc: Leif Johansson <leifj@sunet.se>, Eric Rescorla <ekr@rtfm.com>, tigress@ietf.org
To: Prachi Jain <prachi.jain1288@gmail.com>
References: <866c814027bb35ad96524dd451eaa837d3318a61.camel@sunet.se> <CABcZeBOAXWTiDPMku9TetF5av5cJ5DOVA5LFuQpwUNAvPMsdRw@mail.gmail.com> <6e11be7cac39b5f6907d4255fe09e2c8113a1a4c.camel@sunet.se> <CAA1-vB2a1kX916rCixqP-VD7NLUu7zR5j0YX=saHwmDXyZXbjA@mail.gmail.com>
X-Mailer: Apple Mail (2.3774.300.61.1.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/tigress/z2P1m_s0s9SRbjyFPle7W-uyy9k>
Subject: Re: [Tigress] post-118 direction
X-BeenThere: tigress@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Transfer dIGital cREdentialS Securely <tigress.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tigress>, <mailto:tigress-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tigress/>
List-Post: <mailto:tigress@ietf.org>
List-Help: <mailto:tigress-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tigress>, <mailto:tigress-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Nov 2023 20:28:13 -0000

In the context of Tigress, secure invite_channel implies the following:

1. The {invitation} goes from initiator (A) to selected Recipient (B) with integrity protection.
2. {invitation} only goes to B and no one else has access to it while it’s in flight. 

That means only end-to-end encrypted channels can be considered secure. Channels like email or sms have well known design flaws and should be considered as non-secure.

In building a Tigress solution, we are not restricting the invitation channel to only end-to-end encrypted channels. We want to allow existing channels like email, sms.


As far as I can recall, in 118  the orthogonal option was introduced as an alternative to the not-secure. I align with the idea to acknowledge that not all invite_channels are secure.  

Our path forward should be with base assumption that invite_channel is not-secure. 

It would be good if more members send their opinions here.

There were fair amount of people at the mic who voiced against making base assumption that invite channels are secure.


Thanks,
Yogesh




> On Nov 30, 2023, at 10:30 AM, Prachi Jain <prachi.jain1288@gmail.com> wrote:
> 
> WG, 
> Chairs would like to hear from more of you. Please reply to this email with any feedback you have. 
> 
> -Prachi
> 
> On Wed, Nov 29, 2023 at 3:14 AM Leif Johansson <leifj@sunet.se <mailto:leifj@sunet.se>> wrote:
>> On Tue, 2023-11-28 at 20:27 -0800, Eric Rescorla wrote:
>> > 
>> > 
>> > On Thu, Nov 23, 2023 at 6:01 AM Leif Johansson <leifj@sunet.se <mailto:leifj@sunet.se>>
>> > wrote:
>> > > 
>> > > Folks,
>> > > 
>> > > The chairs have conferred and we recognize the following consensus:
>> > > 
>> > > 1. assume that the invite channel is secure and adjust proposals
>> > > accordingly - at some point we need to identify what (if any)
>> > > consensus
>> > > exists within the WG to pursue a solution
>> > > 
>> > 
>> > 
>> > This seems fine. And I think we should identity that consensus sooner
>> > rather than later.
>> >  
>> > 
>> > > 2. address invitation channels that are not fully secure in a way
>> > > that
>> > > is orthogonal to the solutions the WG decides to pursue for the
>> > > core
>> > > protocol.
>> > > 
>> > 
>> > 
>> > I don't understand what this means and I'm not sure that it will
>> > work.
>> > Depending on what assumptions you make about the system it may
>> > or may not be possible to address this problem independently.
>> > 
>> 
>> I am merely trying to reflect what was said in the room at 118. 
>> 
>> Several folks expressed an interest in trying to find mitigation for
>> *some* situations where you want to use an invitation channel that
>> doesn't fulfil security requirements.
>> 
>> This I hope also answers Yogesh question: The assumption that the
>> invitation channel is secure only means that if you want to use some
>> channel that doesn't fulfil the security assumptions, you need to add
>> protection either to the message layer or to the channel itself (eg
>> adding TLS). 
>> 
>> Point (2) in our consensus summary just means that the chairs heard
>> that some folks expressed an interest to work on certain solutions for
>> adding security independently from the protocol itself. This may or may
>> not be relevant work for TIGRESS.
>> 
>>         Cheers Leif
>> 
>> > -Ekr
>> > 
>> >  
>> > > 
>> > > Please respond with your support and/or disagreement. If you
>> > > disagree
>> > > please provide whatever insights you are able to.
>> > > 
>> > > Also please indicate your willingness to eventually implement
>> > > and/or
>> > > support the results of (1) and (2).
>> > > 
>> > >         Best R
>> > >         Leif & Prachi
>> > > 
>> 
>> -- 
>> Tigress mailing list
>> Tigress@ietf.org <mailto:Tigress@ietf.org>
>> https://www.ietf.org/mailman/listinfo/tigress
> -- 
> Tigress mailing list
> Tigress@ietf.org
> https://www.ietf.org/mailman/listinfo/tigress