Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00

Bodo Moeller <bmoeller@acm.org> Wed, 15 October 2014 18:09 UTC

Return-Path: <SRS0=qaHA=7G=acm.org=bmoeller@srs.kundenserver.de>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44DB51A9036 for <tls@ietfa.amsl.com>; Wed, 15 Oct 2014 11:09:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.938
X-Spam-Level:
X-Spam-Status: No, score=-0.938 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RlUC_Tds8Ofp for <tls@ietfa.amsl.com>; Wed, 15 Oct 2014 11:09:48 -0700 (PDT)
Received: from mout.kundenserver.de (mout.kundenserver.de [212.227.126.130]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 69D401A903A for <tls@ietf.org>; Wed, 15 Oct 2014 11:09:47 -0700 (PDT)
Received: from mail-yk0-f169.google.com (mail-yk0-f169.google.com [209.85.160.169]) by mrelayeu.kundenserver.de (node=mreue001) with ESMTP (Nemesis) id 0M9B9x-1XSbZc16wH-00CNgn; Wed, 15 Oct 2014 20:09:45 +0200
Received: by mail-yk0-f169.google.com with SMTP id 10so810786ykt.0 for <tls@ietf.org>; Wed, 15 Oct 2014 11:09:44 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.236.19.232 with SMTP id n68mr19569382yhn.27.1413396584214; Wed, 15 Oct 2014 11:09:44 -0700 (PDT)
Received: by 10.170.194.15 with HTTP; Wed, 15 Oct 2014 11:09:42 -0700 (PDT)
Received: by 10.170.194.15 with HTTP; Wed, 15 Oct 2014 11:09:42 -0700 (PDT)
In-Reply-To: <543E9FFA.5030102@redhat.com>
References: <2112FCAD-4820-49D9-9871-6501C83A554D@cisco.com> <5438CFEA.7000401@brainhub.org> <543E9435.8000905@redhat.com> <2A0EFB9C05D0164E98F19BB0AF3708C71D39ECE9C9@USMBX1.msg.corp.akamai.com> <543E9C9F.5050104@redhat.com> <2A0EFB9C05D0164E98F19BB0AF3708C71D39ECE9D5@USMBX1.msg.corp.akamai.com> <543E9FFA.5030102@redhat.com>
Date: Wed, 15 Oct 2014 20:09:42 +0200
Message-ID: <CADMpkcLprz8Ag_6hWsrAudNDRH1EP0b7kV9E8JXWtFRfvZaOEw@mail.gmail.com>
From: Bodo Moeller <bmoeller@acm.org>
To: Florian Weimer <fweimer@redhat.com>
Content-Type: multipart/alternative; boundary="089e0163416e5439c005057a0950"
X-Provags-ID: V02:K0:Fo9NhCOM0mN1SezlB4qrveBp63w8OD8FBEfKf9ONy+3 fZrCtCK2eq2j2I+yL9VDk60Jxh2W1zFvZ7Xo4XBQPf8rbYNbEZ Y9q9t14SUaMZcqmrn6fiddzVnVJdGBqaD1rUnJwCSXdPdbkdTu xvYeUY6ZwMpcWyc0WdiI9n3aORTOPDN2IrFvFBUjM7KcjDAHRJ g1M2sdWcq4K0Dlzbg/qXIUwt5+qYhWpfQdZxQhu/zL/IFZNueW MnnhSmW47yk9yg16ZsWGTwEyqtZjcq2l2MrwnyN3zLhFwYk20L HPJnNc2HjOpq3Nv4aXPUt5DYoH+ke0kLAnNqydMYvq6U9p+wDF her+2K0z1yUk4W0Hb0GdLtdBlPb2oUFD+kbxG9T1q1k5q6XvhT RDHNHUmjdtm8qTBuGGw9Sw7Fobc8g3LyLUbYi/lTIC/F/MPBox F7/xv
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/TcVkE0gmtUNp4-jQdTjUBLPDog4
Cc: tls@ietf.org
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Oct 2014 18:09:49 -0000

"Florian Weimer" <fweimer@redhat.com>:

> I'm concerned that a straightforward implementation of this new SCSV in
Firefox will introduce user-visible connection failures when the downgrade
is caused by a (likely spurious) networking event.

This is similar to spurious network failures if you didn't have fallback
retries at all. The details of how browsers do or do not retry in response
to network glitches certainly are out of score for this spec.