Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00

Tom Ritter <tom@ritter.vg> Wed, 15 October 2014 13:41 UTC

Return-Path: <tom@ritter.vg>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6CE61A6FA7 for <tls@ietfa.amsl.com>; Wed, 15 Oct 2014 06:41:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.079
X-Spam-Level:
X-Spam-Status: No, score=-1.079 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Iu-djstXiwM2 for <tls@ietfa.amsl.com>; Wed, 15 Oct 2014 06:41:41 -0700 (PDT)
Received: from mail-ig0-x22d.google.com (mail-ig0-x22d.google.com [IPv6:2607:f8b0:4001:c05::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E50401A6F8C for <tls@ietf.org>; Wed, 15 Oct 2014 06:41:40 -0700 (PDT)
Received: by mail-ig0-f173.google.com with SMTP id h18so17344302igc.12 for <tls@ietf.org>; Wed, 15 Oct 2014 06:41:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ritter.vg; s=vg; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:content-transfer-encoding; bh=/1myMsigjb0AqG0Z+AxjBJ/izOjog9hkM/+XbldBj7I=; b=Vj0q/lmNCWP/iOoUyEVPeWHlWychCAg/PYzBkP358EfKKl9wdpCbUbuZqAQO03wbnO +aB0Rr05yJlkgts3aDNl7Bluhje1ay+oWI04E2XCmmAP3ZJhEJHwaJwH5+VpTR85ZXvz zKjjHwPigBArIvbraugF02ZzLx0Rb1LDkXoSQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type:content-transfer-encoding; bh=/1myMsigjb0AqG0Z+AxjBJ/izOjog9hkM/+XbldBj7I=; b=avrTTPyyKg86kx6Ka5bYkvO/WxR+MDZSBBJ6pv/mfwzmkwfnnjm7Cv4Wl9sDPDLPpH QvgXrW6AsFxsmwHDpuqyDECre8cdx+4oP0YbzxFPLvGZf3Nt+Qs4uyQuSnQOLGE7mmvN ieVl/N5+AoESQuiWsNg1c2YGizmok9CZx9aSSWBX++En17uAHOw7TrN5Pul5zhwLUxQ9 a7XQmeVROlgmql92KRqIIGD6BZJoXQErcpc+hFBsh2ocklsIzqyzCTfZK/QSsBqMnvAZ n+hav8KckyyPAmzrPMFT/66WrJUo3wYWYavcvi8xfJkgZMFrhnRXYE+cM2oIHh9bpT9N cQLA==
X-Gm-Message-State: ALoCoQkRKxYPk3C7vNPEEO77CdTMCWrYxleITLFjX3RLyVrMjB267T8w+8zpi2zyNx5JqhNjNZ+O
X-Received: by 10.43.94.7 with SMTP id bw7mr11411269icc.30.1413380500134; Wed, 15 Oct 2014 06:41:40 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.107.17.15 with HTTP; Wed, 15 Oct 2014 06:41:19 -0700 (PDT)
In-Reply-To: <20141015140158.41a1faf8@pc.my-domain>
References: <2112FCAD-4820-49D9-9871-6501C83A554D@cisco.com> <543E2D81.1050700@redhat.com> <7F8CB03B-6882-41E7-9705-7126A8F2F44D@gmail.com> <CADMpkcJLrQEtiUGi9B7ZS5402cXTBvvThL9-YwUUhncaXQaVsA@mail.gmail.com> <20141015140158.41a1faf8@pc.my-domain>
From: Tom Ritter <tom@ritter.vg>
Date: Wed, 15 Oct 2014 08:41:19 -0500
Message-ID: <CA+cU71=VZyqLaLh_KVQ-2nVpBR_OPOsMUk5Cw2UKcykqiYgLoQ@mail.gmail.com>
To: Hanno Böck <hanno@hboeck.de>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/JQVozchnPuWyDv8UlEmqXY3WYoQ
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Oct 2014 13:41:42 -0000

On 15 October 2014 07:01, Hanno Böck <hanno@hboeck.de> wrote:
> * Support people who deploy correct implementations, punish people who
>   support broken stuff

I think the last bullet may also be stated as "punish users trying to
connect to broken stuff".  As Bodo mentioned, browsers would like to
remove protocol downgrades, partly because they represent a security
vulnerability.  But the priority is to users and not breaking the
Internet in these situations (hard-fail OCSP is another example, CA
blacklisting a third).  The constraint we have (putting up with the
downgrade dance) means we have two options: deploy this SCSV and
protect your users, or do not deploy it and don't.

It's fair to reject the constraint and push for a more perfect
protocol, and in some situations I agree with you.  In this situation,
I accept the dirtiness in the interest of providing a way to protect
users.  Perhaps this should be "Informational" or "Experimental" to
try and isolate it from TLS? But regardless, I would like to see it
documented, implemented, and deployed.

-tom