Re: [TLS] Publication of draft-rhrd-tls-tls13-visibility-00

"Ackermann, Michael" <> Tue, 24 October 2017 16:42 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 4ACFD139553 for <>; Tue, 24 Oct 2017 09:42:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -4.09
X-Spam-Status: No, score=-4.09 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)"
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id vdtHO0HkN6v5 for <>; Tue, 24 Oct 2017 09:42:00 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 052661394EB for <>; Tue, 24 Oct 2017 09:41:59 -0700 (PDT)
Received: from (ZixVPM []) by (Proprietary) with SMTP id F21491C0A16 for <>; Tue, 24 Oct 2017 11:41:58 -0500 (CDT)
Received: from (unknown []) by (Proprietary) with SMTP id 527AB1C0750; Tue, 24 Oct 2017 11:41:58 -0500 (CDT)
Received: from (unknown []) by IMSVA (Postfix) with ESMTP id 1B311FE064; Tue, 24 Oct 2017 12:41:58 -0400 (EDT)
Received: from (unknown []) by IMSVA (Postfix) with ESMTP id DAE00FE048; Tue, 24 Oct 2017 12:41:57 -0400 (EDT)
Received: from (unknown []) by (Postfix) with ESMTPS; Tue, 24 Oct 2017 12:41:57 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=selector1-bcbsm-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Ou64pP4AbE70W0620ze1LDUpWAVpww6n2bPt+NB2KYY=; b=ZZFCkP5fzTHezkve7bNLefxohnJzx1rPx7jE4HGzoNMeuST4qf68YWx8Rzql+xeeed5BP8FwfhxkFUhQiv/wd6ctTH+UKPCdIasKJvKGAPOEsFOj4l00243I3WyrqDk7A2YKv34g0t8n21ajxFMy0ITUQwkzbo8byFndtqe0Qjg=
Received: from ( by ( with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id; Tue, 24 Oct 2017 16:41:56 +0000
Received: from ([]) by ([]) with mapi id 15.20.0077.022; Tue, 24 Oct 2017 16:41:56 +0000
From: "Ackermann, Michael" <>
To: "Salz, Rich" <>
CC: "" <>
Thread-Topic: [TLS] Publication of draft-rhrd-tls-tls13-visibility-00
Date: Tue, 24 Oct 2017 16:41:56 +0000
Message-ID: <>
References: <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
authentication-results: spf=none (sender IP is );
x-originating-ip: []
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR14MB1366; 20:tSO+tvzAoYDKqvzzlhquHO39MddPZZB32mufL27x21lWotAogTW2pcylXr6s0ttCPw5fBzMKJHsbRrujAWOU46bX4cuYuvbUtrj1e/OgE4JuqXJ4JOnU2iY43eDrbAxai4F+Ns1NpheUP+B+l+LZGDSiKAUdi0QAodfIVT3ZzKA=
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: c07d235c-3f36-4e22-2ea3-08d51afe238b
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(4534020)(4602075)(4627075)(201703031133081)(201702281549075)(2017052603199); SRVR:CY4PR14MB1366;
x-ms-traffictypediagnostic: CY4PR14MB1366:
x-exchange-antispam-report-test: UriScan:(190756311086443)(86572411397741)(244800015338608);
x-microsoft-antispam-prvs: <>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(93006095)(93001095)(3002001)(10201501046)(100000703101)(100105400095)(3231020)(6041248)(20161123555025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123560025)(20161123558100)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY4PR14MB1366; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY4PR14MB1366;
x-forefront-prvs: 047001DADA
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(376002)(346002)(13464003)(199003)(189002)(81156014)(81166006)(7696004)(5660300001)(93886005)(230783001)(66066001)(189998001)(478600001)(53936002)(8936002)(33656002)(2950100002)(16799955002)(6916009)(72206003)(7736002)(97736004)(8676002)(2906002)(25786009)(77096006)(102836003)(6116002)(3846002)(76176999)(54356999)(50986999)(86362001)(53546010)(80792005)(966005)(316002)(2900100001)(305945005)(68736007)(6306002)(55016002)(101416001)(106356001)(74316002)(229853002)(99286003)(6506006)(105586002)(3280700002)(14454004)(4326008)(3660700001)(6436002)(9686003)(6246003); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR14MB1366;; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None ( does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: c07d235c-3f36-4e22-2ea3-08d51afe238b
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Oct 2017 16:41:56.2507 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 6f56d3fa-5682-4261-b169-bc0d615da17c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR14MB1366
X-VPM-GROUP-ID: dc40945e-ca88-4605-a5fc-37cf93d46a44
X-VPM-MSG-ID: c4a5c81a-28f3-4288-8701-12c559ba094e
Archived-At: <>
Subject: Re: [TLS] Publication of draft-rhrd-tls-tls13-visibility-00
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 24 Oct 2017 16:42:02 -0000

Our proposals are for spanned/tapped, passive traffic.    You seem to be talking about modifying the actual  live data stream.  
And MitM is also outside of what we want to do but would seem to be more feasible in that scernario.  

-----Original Message-----
From: Salz, Rich [] 
Sent: Tuesday, October 24, 2017 9:30 AM
To: Ackermann, Michael <>;
Subject: Re: [TLS] Publication of draft-rhrd-tls-tls13-visibility-00

➢     The objective is to be passively observe, out of band and not to be a MitM or modify/inject text.    Just as we all do today.  
That might be the objective, but isn’t Ben correct?  If a third-party has the session keys, what prevents them from doing that?  Good behavior?  Or is there some technical means (unclear to me) to actually prevent it?

As I used to read in the comics of my youth,  I am glad that this conversation thread kept going, like a zombie it keeps rising.  We know have enough knowledge to definitively put a stake through its heart, forever.

The information contained in this communication is highly confidential and is intended solely for the use of the individual(s) to whom this communication is directed. If you are not the intended recipient, you are hereby notified that any viewing, copying, disclosure or distribution of this information is prohibited. Please notify the sender, by electronic mail or telephone, of any unintended receipt and delete the original message without making any copies.
 Blue Cross Blue Shield of Michigan and Blue Care Network of Michigan are nonprofit corporations and independent licensees of the Blue Cross and Blue Shield Association.