Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00

Bodo Moeller <bmoeller@acm.org> Wed, 29 October 2014 11:34 UTC

Return-Path: <SRS0=7rtC=7U=acm.org=bmoeller@srs.kundenserver.de>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 358541A001D for <tls@ietfa.amsl.com>; Wed, 29 Oct 2014 04:34:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.762
X-Spam-Level: *
X-Spam-Status: No, score=1.762 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FM_FORGED_GMAIL=0.622, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id maD6zmGx3Oc6 for <tls@ietfa.amsl.com>; Wed, 29 Oct 2014 04:34:07 -0700 (PDT)
Received: from mout.kundenserver.de (mout.kundenserver.de [212.227.126.131]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C61091A001A for <tls@ietf.org>; Wed, 29 Oct 2014 04:34:06 -0700 (PDT)
Received: from mail-yk0-f177.google.com (mail-yk0-f177.google.com [209.85.160.177]) by mrelayeu.kundenserver.de (node=mreue005) with ESMTP (Nemesis) id 0MTtPJ-1XaswP0xpR-00QgwR; Wed, 29 Oct 2014 12:34:04 +0100
Received: by mail-yk0-f177.google.com with SMTP id 79so1167236ykr.8 for <tls@ietf.org>; Wed, 29 Oct 2014 04:34:03 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.236.38.234 with SMTP id a70mr1267061yhb.63.1414582443064; Wed, 29 Oct 2014 04:34:03 -0700 (PDT)
Received: by 10.170.194.15 with HTTP; Wed, 29 Oct 2014 04:34:02 -0700 (PDT)
In-Reply-To: <87oasvp14r.fsf@mid.deneb.enyo.de>
References: <544E9A42.9080503@fifthhorseman.net> <20141029023528.B14E71AF5F@ld9781.wdf.sap.corp> <CADMpkcLLOrUQMxbeCW7RB+Gf12Ux_wK_eotKdbH0RMpeuaptfQ@mail.gmail.com> <87oasvp14r.fsf@mid.deneb.enyo.de>
Date: Wed, 29 Oct 2014 12:34:02 +0100
Message-ID: <CADMpkcLGUYpSvq3ALrmjqEvJGFzkdwAXdxuNq01V88d9YGfbfg@mail.gmail.com>
From: Bodo Moeller <bmoeller@acm.org>
To: "tls@ietf.org" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="001a11c1f68006467605068e246e"
X-Provags-ID: V02:K0:pSW3K5kltrCV7A7yF6QOTLQwESj4D0RrOnA/QmAOYbN 590dRUMMkVVJnRv63QOT2uGlzdnXpHtP0wd9g5GvQvWaRQJ/jY BQQkonFVIUusiCBaalv8+ucHz1cicAGx/AmKnVVEvm7TbtdSBo U6FNVmk7GcuVCsNDzl5SmXb1Yc1Nc6qIgKHqRe3CDYpGO7o9cB GblHx1zMV47IPua+rM9F3pQ9Gnf1dq4MTfy1WBNEloKB5FSDIX hRxekZ/8/ZYbmTHRQf3rVgeLR5CmJqWiXuDOeN+CtbOrM5MmmH g/P//Hqwuah4QfeBAiXD0GAUqz1ql0iov7sZCYTFqrNNNZ8DEG Fe5ZwjNqs+Zg3MdR2fK1THvTliy5MuKAZNG0Ybvu0mBMTPX1pg 0fWKfjO9LZV2kadc6Y+iYV8l4AtM9ln0gCEqqxO+4TU937LFn4 mbPKE
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/PA1pLEjK32vzLjrzjLP3CYGujQE
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Oct 2014 11:38:04 -0000

Florian Weimer <fw@deneb.enyo.de>:

This bug in the fallback logic was actually reported in 2008:
>
>   <https://bugzilla.mozilla.org/show_bug.cgi?id=450280>
>

Thanks! That makes it six years old (as a *known* bug -- presumably the
problem is older than that).


My concern is that this bug has tainted the telemetry data collected
> by Mozilla, and may have grossly exaggerated the need for fallback.
>

The folks at Mozilla are well aware of this kind of problem, and that the
number of downgraded handshakes observed is inflated over the number of
handshakes that should have been downgraded.

Bodo