Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)

"Roland Dobbins" <rdobbins@arbor.net> Mon, 17 July 2017 15:11 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 235F0131C60 for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 08:11:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level:
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yKiMNtrtDWKh for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 08:11:57 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0102.outbound.protection.outlook.com [104.47.42.102]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7227D131C65 for <tls@ietf.org>; Mon, 17 Jul 2017 08:11:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=6c0bHWqXST6YV1RosgW5B/AQ+VvnUMb3Fn7M3Jztccs=; b=l25FnNaJCh/0uo02BedS41bCofFahn+AdUt4HtvdFfkWI4urRufwBtXbmT16zBUsP+AQ1jqovu0/M2LyX8+hurTujGjIQ8feBWF+m5AKQ7mxsegw1CdF3IIZYYOeYW/fUYHMhqSWHcuRokIBasEdhjN3j1p5wpz/hDJofCyknng=
Authentication-Results: ll.mit.edu; dkim=none (message not signed) header.d=none;ll.mit.edu; dmarc=none action=none header.from=arbor.net;
Received: from [172.16.1.3] (88.208.89.131) by DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 15:11:49 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
Cc: IETF TLS <tls@ietf.org>
Date: Mon, 17 Jul 2017 17:11:41 +0200
Message-ID: <69018030-3157-42D4-A573-0E39E46EFAA9@arbor.net>
In-Reply-To: <66C1C32C-53C2-43A4-BCB0-96DDC26A1F58@ll.mit.edu>
References: <CABkgnnU8ho7OZpeF=BfEZWYkt1=3ULjny8hcwvp3nnaCBtbbhQ@mail.gmail.com> <2A9492F7-B5C5-49E5-A663-8255C968978D@arbor.net> <CABkgnnX7w0+iH=uV7LRKnsVokVWpCrF1ZpTNhSXsnZaStJw2cQ@mail.gmail.com> <FDDB46BC-876C-49FC-9DAE-05C61BB5EFC9@vigilsec.com> <9C81BE7B-7C21-4504-B60D-96BA95C3D2FD@arbor.net> <CAEa9xj55jzch-v0mysbRSryNM0Y7Bdtevmrc3+FVxMO8EP5zWA@mail.gmail.com> <CC3CE5F8-C8C2-4A70-829D-483E26D20733@arbor.net> <CAEa9xj5eR6b_+CsSDArMWWr-u8hx5B81kDVEMEX8sgfUeMUS8g@mail.gmail.com> <C3B01C35-E3A2-4A8B-9DD7-D6E4153ED39F@arbor.net> <CAEa9xj6p0y9ZzxLJvtv9GDzzfs5s13nnLqm=4_fNDPGV+=Od8Q@mail.gmail.com> <BE4E8E4A-51FC-4211-A16F-EBA8B3F01757@arbor.net> <66C1C32C-53C2-43A4-BCB0-96DDC26A1F58@ll.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [88.208.89.131]
X-ClientProxiedBy: DB6P18901CA0008.EURP189.PROD.OUTLOOK.COM (2603:10a6:4:16::18) To DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 64e53621-ca40-4d66-a519-08d4cd262694
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(300000503095)(300135400095)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1039;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 3:l0+r/+Dfoh7DTLlGJgQxs9IlaNKK5JhEFTp7DR6P/ag9s2B2jMg/h1cxQgtb4FwTfvEgn7rC9yLt6blCXt4OkuD1WIOVW3NZ4gYzhftNNwrbSNZCdA0ewYtNpAzJwDGh7UBYwqfWy0TgSAqhCrVgdYubIuLQ43W37+6XAu+CM6g4Ua6zqL5t8KjkP0wJBnJOQRoZZt9vwwvKSrYIr7bkik6aBvUgLbm2C9MsMegWdCa411rPzXqovKexhXyhQeSHvrFLe7kJeQ0SzxbI/WYtRRq2fs+vWz9XvpY8Gpvoj60CQDlfQ2vat9/IlJ1SUr6zlvA0PiTZ6uq1GRbe80gL6kALdy6iC0jaexUT2/4tpUuNW0X1wDt0bJZv6sNc4HE1dK4nJPh76w7Bp1l9/+ewICKP1PebpSxUlBl63TampN9yR0xjaHzoey0l6BPM2fbeVDdbc81VxZVaASVSzw0AFHfty/a5cS67FGWA4A/3byVN8EQrdLmV8Hx8NRPxigf2wnpn2InhhUB8X1CObKkMsF+6O5sZkucd5jjlx0M0bcbRwX+Gg9aKfSGdp4hpY4weRDIwvVlYOGJC/rn2z4bKPiJT/hqjLlbWBAvb+fdXBTZqloSjwzdZfs6og8zxg1nobiF0yUh6FVvgJRXaBpDGgG79LVuQSvhia+GM8sSLDGvJisVk05Z6wcVRlc0aZEcnr/DzyfMJQt95fnKduq8JuP1DOxXaryMtRfzK5VjcliY=
X-MS-TrafficTypeDiagnostic: DM2PR0101MB1039:
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 25:sns9fbj0FRqDETDH+8FiOd+J+B5IqD/1JJC4+FnhuqVMJ5fOlFYL9ghoQ+XprZAh7JXOvSQpQe5uC3282i3ZDJyw6MH2OZMc9SKgyb6HmfZ9dQUa3H2POnHcboVCRwSO576Bs/ljMTuv6YpRGXz2BkI8sS/FI9d3rTtt4Zm+cF7clnHUXv496VNdd2oA5uQpeExDCAw5tu4PIFXxAfb5IgEjCXSnfHx0WeGM/taTcze1dEtILD1obJn+VC/gnoGrj6k6P1cDSiBT2h4u2hcAK5dbi+rkPcfYuWN6yI3EiyrzswPGbSR1G1a+1Jp6r39oGw0okC2UsHTFiB+l2U7XMjTvT/u04RXotnEbvVhvBJg2bmvb9dqxKccC2/nLdiANUReZLfBi7Pz6AxU+/Q7xt7a4cIbkYVp4XIQhp3655BuZLNt8DVkrrJdwOGaVSgvayWYearzwuhVPJCK8GlmQ4ljddwrCfaxWoKuHPEHhUS59OcnuYJ5e5BTyzKJdhRTGSwZWXykLPrC9AtblYcpRB/b6QjolrchduBGOFJSnU/hlTYzCYb2gUrshNWZOVp+WqiVsQ+VNK3iLdpPA9npcA+9RBGef06I3afQsZw0/88aipe+DQQPgVHOi/P+5wp7jzeJ1utOqpW5yIW5gsDyrbdPAbSujjhDpGXFkJEAJR3ZT7960ANQ+4hapEmdvDrME/13eXls+eAT0tHyGSQPV7IeYusjJPDPQ3IczbelFPvMKU2zfXZe6W04Ug3AfT84I2npHIkqy0/l2kG78LA3F6pHrUENyZgUHGckwl9fdnFye8UlqUj7G8WrwgzPshCmqksCLnSX1wYqcquRiqq0+SRZkDJvkTIIvuZnF47Tc66g3weCZY3KBJB89wN4M20eb4vWQEbqZ7Yz+MIW/S3IMgOOV/DZJ4qHbNf5OcY8GTXU=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 31:Z+2RT7TN25rORT5sfLdkXXM44Lr6/2Xc3a3mkiDmuFhe1xaowVEPUd1FYQME8HKX+WvJ0Z/c/UwREVSE4wFVdycA4WMIACdQ64LPt+O2ClwVI27zywaIUdVzYxnPsZ53crnax/ccIs36iQ7x0FRp44jp4xg4PDREBKn9HZqsi2wkl797re/HKFGO+eK15hjhn5XpOkM0fkTj2c5+jiinR4DzfgLmsolyboiMFqL+FB19Z2v+hOSFdCgMC3P8cKcFq6/DemZDmzCyPNaAJqnAs7Zdw8o80l70NO0NrywKptGUMESEjFYQ4L++aIvjX8UvF842haqT05K5PqUnch+gYbgBeg/V9tPZV6erReH6ACqCCN+b8Z8bkKMv7jUwdhW+Y1IT0k8xkHfnkkqO5TaRGJyWP4VNXp+NU5VY9XCnoQMZsNGLSA/9Ly+iK3jCC5pUJmIn1V7BC5AyPBlCo8woaLejQZ5qg1B4qQKxyCsjHDGYcmgKNAKVJTPqpjSWvUZNdZvZDQ3a/mqbv9O6F59vYWO2aQsZ5J1ceSkjHxfqEpLElp07sr1zPWSNiDy56u30wZ0SH3u6btdC+lKs/COt112uOAVY9DbxiNaoVNzCMqu2ycIYO2YD1JdcIyfPgQjuUuKJDeiGNrB/ZQ61w9jxX9dx3CLcIY+yQSrdA8miyp+tdqqkgcx5dQJ1ZcZ+Z9lwcPWjfy6WOO/liZqNERsD5g==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 20:fVtWaHSt2Ce6k6BTcvBpbkuKEAolJsCkSLnNX7GfixwJ1Wl6KPneHYpI6Hj9Yj8gOevt9dc9GGMhn8ZlRXq1PfOlgtKHBcJq+aBByLV7lTJIkllaeXQYoqOiVBQuZp3QKNkiRr3xp+QmuRnGqkioX/9QBYdjAAAQEO3zAHt2vWHtbqM27HmkVoZ+qFKBTM5SzG5V1AbTxvjglhaPpcuNKsmB9eGdrhuZOBxWQn3MBmQCaAFriAf8p6agGwLv3EtaZjnwuCZNgzPmpZLVZf5xoI94G/oKc6to10eULWxtk9G4bFWOd1PjAbUG5jNPXpB3RjYjE+1L1tfG8f0mtE5W+BicT3c8uWAsE4K8AQd+kyWpuq3o6PDe05IBbHFotzQQfUA7cW2zteO7IPUuCx1r/ADjwkx5PXUj1sfCd2I/tM3Jk/N9hKkr8cn+3azDfBI/lzpJe+CRrWZAOCRBOeWP3qrZSxPbO7DN1WuC3d5XGMQdaKbDxQCUH1jBPvlsWTmO
X-Exchange-Antispam-Report-Test: UriScan:(236129657087228)(192374486261705)(48057245064654);
X-Microsoft-Antispam-PRVS: <DM2PR0101MB103929507441736A4240AE06CAA00@DM2PR0101MB1039.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(2017060910075)(5005006)(8121501046)(3002001)(100000703101)(100105400095)(93006095)(93001095)(10201501046)(6041248)(20161123558100)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123564025)(20161123560025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1039; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1039;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0101MB1039;4:SpKorWgFkOgQcTQPQCyzD5c/tAtatZ4RvuoqalOZCjCcpO7EKQe7XC3yb7hL2roPcM3MXF+xMTQ9Qh2oNi09McIe70B0DwkBrQnfbXhFBhF7svN/F4iR29JHuDfboDKF/b2jKx8QpwKCw6itdXpjeaAcx6spLDTeWsVxiRKF+UwirlNjbupabqJx5bryiYoen8xwBECGbl+l1+/L1guW3h/5d8NC4sLUyhqhdgKWsT3N+aWquLCRgVkji5s0Wnocg9hL804j4OMXPmpzUSVR+5Kp8lE6hbx67qxePKDwkA0S6TfwYEyF3FGR/35Q+OtNnbmp/fRg9/LNuSWKzEGMxbMSuufCNfcCksPvURjNueDwV7YEII6iMtXyxFt00KgLI0fVByzQrv+f7eXlrqlVZbO0r85LWr2cH5mYHS/RJLzcNBR8cVNFsT+EyCFJFUVaTRKb9iFVkZJ7e/U0mRRr9unCUswRH8rO2hIhBRavkGwea+f/rrWdL0ein/DeFsnOcTHcySMk3wMGV3GLaSeUKgu7kEGguLtSL2QU5kLUcte2dKUkkNlr3SM6BnXRqogs+2Dt2/nqd0GdRrW6QJqyLnlV4GlifmtWRK2ftaehCLmblZ8H0Y/pHpZFIkqGL1q/y3XbSs+2e6Da/9YSbv4t1M3bApbMzd4OuVMy8/1V3KgUu95Vc2IphoZ8IE+Xbm+eTdAXLXTg3sZDDf0HmsLZW5IS+skgpdlQQeF9SMv6i5HXBp25ZTkOskjVS+Pg2sLsK5oDZvuhGa0y7/M8mRS3REBMNtzLGcAgAcRrKCIVdwFgWPc49yZPF+xVdkzgbcLld/Pfk6lDC4aqGmT30g13jmIFzRNLj4NZto3MmsdwtsZ2G83XtpvR/kE8hExVaQg4pMvE1LD4gwLhv4mSdSePvBztxk23q13i88D7EUOIAgl0BjCrJSPluNmgl3WNfq6tVpARaNG4kSNpA/2BYAPt1KdCBIwkR7NhzJAybQaKc8XzJOg7TI5oIT18gW+QNp1KCUduHZVNrRkJF28wimsyFcAPKZbhRv0gdu+eUhau7JFSNlxL+Ru9SV/cGrnsEhbAUKHDx5Y6SpBGJe+3d3yPqygQ8/5dtwGStUN29Q/Gn6v8t7GTCQhFLUqPhVy7I8JTZlFiY0ecFgkyRvnTxk3APk2W/omrY+AXb3T63JdhuQhTlQTVERZhpJztQKrAd3wGJ9ah9EnxPjTaNKDytXwB+ddtsQ/bN4N054Z2Rww9Ckfe4XaOYO80PwN9oqFjEo5m
X-Forefront-PRVS: 0371762FE7
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(7370300001)(4630300001)(6009001)(6049001)(39450400003)(39840400002)(39410400002)(39400400002)(39850400002)(24454002)(53546010)(478600001)(189998001)(7736002)(8676002)(33656002)(305945005)(50466002)(2906002)(229853002)(50986999)(76176999)(47776003)(66066001)(50226002)(4326008)(53936002)(6486002)(6666003)(23676002)(77096006)(2950100002)(6916009)(81166006)(25786009)(2171002)(36756003)(110136004)(38730400002)(7350300001)(6246003)(86362001)(83716003)(42186005)(2870700001)(82746002)(93886004)(3846002)(230783001)(5660300001)(6116002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1039; H:[172.16.1.3]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0101MB1039;23:6O17FB+S0UE70Jjg/viONcrq25I7tBVNa5veicewCs8UJ6g9iqq8SX4w/gLnXuLAYIzHrEFPSRKsGpeiQeH4leLkwfl+D0g8h2YGifPxkTx60YzoRqjEHDx9baU7A0pEIv9M3W+hTEQh4q+2GIJcKWhTwNYD5auLgiNrSR30DbcOC57bqz5IVMalBZxpV8tSoQlIqPZFXwFT/paJyjdMiqDzsxJcE6UK+0fJp6pOY0qPp6sGn8t++HVAm56HuuNm73HKYehf+Zsf+YjU9V5VUZjkUwGvXC/AQQgdOjzuTK1MFjRPBNbXrlsBWBlUXvxcMz/fwmlGj8BcX62XQu+N7PxbRcXdrR+15yT6vitMt05DNzNmJgzb+tJyBX4pXXlNwffcy8SFZqKZx1+KPCgl9Gq0S8xJdokXY0DjhHudVRnlf54ByBsBufYn74plg2OsaN51BTfSZ9Zwnh2zux+602c4PMKJY3RRGku9haCuMkxeKoUeyf+gJ32Ki8DTlnXd/LcEtcJF2446oau4xeSItmCyDVlZ8XyhTiQmge1Qvwgcv4/n+kULQWL/OWaUIUNkLKmD2LzdxUNn8EyxTesPGs9i8q7ATYvO1YQvWXAMRuYc8vvRD94BUs3MvKRdbFUBcemAktC3LXZDYX/CJz1w9oEBnZtQhbXmAWQZSnf0EOfr4D4w6LC20t3JQBkPfT+cs4xLeNby3fhuak7kHDjiUEaOGDbo94G94tksyEMctNvCCj06WOjgRoRV8qsmYY0SJnLkPaCk57Z9rFi6n5byZhFSNdKnPlC9/4b/U3VKcSVaJCRxZm4Aw567mgtSs5oyUoUwy7g2zqyGfcorfz5GCOiBP1Jd44OTR37sK5YdPO40wGJatZjUa/VsBy2slo/teBBVLwx0O+QMvlP3zXr9TeP3StQgoKHmDTDg4CE507LJiCPwt3rYQ7LXUh4A5ZOS4qRqSELejCO3CkOVVMfWG9XQkCw6f8KFRdSMXDxtHq0lC0RSbrlhs8s2iYMxoY75dpm0QW/9JcaLK92hyPpaLoMJg2rC4qVSY1FJaA7ggfJmoLaxuOfKEfazM4LsbiwrYyGSUaJ6UfzdtIDG3hy5GqJCUwYATwRYxr9mKO/SDq3712VwquvS+Fdw9PH6vii4KPDmeKIcbV2oSFVku77plmEGS0Y9ISBQhRzJgEqJcEdjaimeYoQ7xjnnZq0uZr5oP0x0+bHCqdKtsG5Ux6cka4bxTeo07MCg/7RNEKLj3Td/Ii396dbabQXJz2O+n9Q/
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0101MB1039;6:+XkfEWaOM+W5utLrB3Gffxyi53eN8Wl1Rjg8BgJgfAcS70BGAtT0mN8+hzj+eFq/QcwAQSlH5JF1OLrrg5wIuQ2SaI2Qn89e2zJN3zobsq9QzqTFp7SH2gEHHAjfuKMLpUum17/BCNH9eWOT6+1NGtR16EOoiCw3QHPZtQpIl5jbhHiga4HbdxqFWFeQKe3sOYt17cYWbcn4OvHaMsnzHNlVyBZkg6djnQy4QB82n+MQwZhi+IF19GBAfovSm2lFJVIynihnIbQEnFQA/Bl6WuRKZsztqsYSHNyJ7sih/KSqWhndwpVSi1VaI/2N6Qz1HA8bsNuPgQmrTb9oCyo5hcIsZ+1p2e1zgTT1HCR0cazyXMwsdP9KFWzaTduJ8LaW+2QEZAqWKNOrpijcuOYqzZtgE0PFDTZrippkOHWkcGkGbY2qiCe29pRV4ZxzFVTsg5J3ng+GjYW7zAPzcfs4XetPrP2lsikXV0FiMAoORaLS8O+J4IpbqCzKJ45wIW+zo7hMZEVyHJcBsVtU3vz2SKyeSDW5AU3FDzcyV9aXj/37o4seAglUemBPkFDzrFix/uy/Q7HoQbasQ7QG3QX/fx90hKHJaMxsnJtWsMjZW7AY80KRmD+IWWm8ht9fue/RkPhe6UizkMtwHZEiwRoI02MNyZBE27SvWtkJgkCy7nVwACpxR0vknNEzjkbkM04MFrPkK6Bme8x6cDpcOSN/LPItT8PAtSG/jXy9jXRqLW5jLjX18IwJOOb7D3fHL7jgDXJ5+zCMj8ABH615WmSIG0v+BfYF+7UfXK5EZFT3VsQVjMoy7Ra9usNw40I+ANKziiu7f11vHHEk4rOVzKdjDXQuPaYKVe9T7RfzSLLEagwAYMQJkgnvzMaZwar9cq7bExsGWPV2fz9v0XUzpWbVruNEMJ0S0n6xE9y/4O8wFiX9Deet4NT4ivvciztIP90QothBATMgXgHFG4ygpaOlwcE2URH3WugTx7wcJSImqJc=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 5:YruFPnTnsQCE0r81Sy1sbnFw/CTsNYNIz9lv6H4D2J9+3qYymZvz9V6goxYuRhIRecFn/YmABo1tU3XSYn53jLVtzIa7Azr8CIbtkzBoWb5a5QFa5WolqObWYh0PR8Olq/pWEYC40xyun5/KeWst8qkR0UJ3fzh9bpiKXdiSNA2+dZD6bN1vJLM2C1oTgl/HTEiTl9gHaJ+L9JuOxxZWql0TgpfW54Jn6H1dIE5uQEfXe9p2B3qXqGTGe9U5993RLvoIA1M8f5HEVmiVbqpn/IKmhNOxalPVaVnwV19WhKHV+nXrj39pliZRjD5dVlFaaRbKt8TzlALunLEiyj6396PCndt6m2noTWpDEFOP0wztXradTl1EgnpjWbCpKIn+AWOTiXStyeAUWF1FRebaWFRmbb+08Gsg+nuYsgdN26q95HZm7J+6P0hnTtX5NqaDVDfm7aRHkFf8bdh4Da6MSs+9ho5XND6ZfaA10SzWg9V/j/D0tRsHqYMH0jpvTuu7; 24:+9B64H0p8qZ6tg+sCedn1o32rmPCt5GSuWLRLVFFtqwv4KduX3N8x1fx72M1iJrxmlZq+VxFoVBo1mkcKyqpOdCIGz/K+dE21sBwsYuyRCI=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 7:OGBCa7heXnqOoxyOwJiFB03UcXt4v0q8ZiIxr1SH7Qk3isLavsZkiCTZnZ7ylUH6wnEMes450IouYETgzSHWKOAYwQqCOCK/ffpjjVGr3drO4DxpmwBJzZg/Wdi4Tflfijh2XApeqf6kEnEkmBmaj1349krduoOvS5jGT9lYYlK9iWo3/CCWffN2McIsH5ZUIRDt2ArrBGI6OqmwQowL1Nr7kcTveJYaV8caVNLrqHv1NxrMyN0uPm+Qn/B57rCnxb854yERKfBgywIWwnEjhcmbr3yZkQxen8nsvzgRDb8lveUfLOsUZhl4va/tmNmXFOOcIeXDaVyKcBS53gO0fUiC4aQq8+j0nYyWNM5YGrJ8a0TD2kYyLHP68JtS4EAYi1rcB12EB2fa4tF/tJUbLoeoHfxyv55e+mqaHnqmHgls+7bvYwuckOCtacCfbRpUs5utEV4lqHPTlElxrc/46j10kjVh8OfWiajoifHi273dVn981e4WDaS+WePAEeYA3wljd+8K7vWDZw3jT+fj+piI0yfVOmaqptzAJXt7WIrzxvSC0yusZzVvuicKE15JZ0JNaMxPChr92rWqChWkcdpSgSIYFFzJ1IV/xXFL3M0v7t67+8xhzkVpM9QlzPOKjw3f93ej3M44G7B++4csy6deVV6tDWwx04DsqGP5VjvpU9UprpA9Isn5XSgQO72Ku2mo7RngDzWHYhXQViwaNymTlzj/HQ8Pm9KVZV1x6dZ3yK6R+I4utBCLBwbQb16lJQKgi1V4v/q6alBLQ4sk/+ptKiy7dJwh9C0SiQG+TS8=
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2017 15:11:49.9872 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1039
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/hjagz8AJJI-2-rvXGH5mWKUnwUs>
Subject: Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 15:11:59 -0000

On 17 Jul 2017, at 16:23, Blumenthal, Uri - 0553 - MITLL wrote:

> It may, or it may not – depending on the sophistication of your 
> adversary. It is not given that you’d be able to “simply detect 
> the presence of an additional crypto layer”, particularly if 
> measures are taken to hide it.

Sure.  I'm familiar with those counter-detection techniques, as I'm sure 
many (most?) of those involved in this discussion are.  And of course 
there are counters to those counters . . . it's counters all the way 
down!

;>

> The standard definition of “traffic analysis” is deducing 
> information from the metadata and the patterns of communications. It 
> explicitly does NOT rely on knowing the content of the traffic (which 
> is assumed to be opaque).

That's what I was trying to get across - that uncovering an unexpected 
layer of encryption, even without the ability to decrypt it, is very 
useful in a security context.

Sorry for being unclear!

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>