Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)

"Dobbins, Roland" <rdobbins@arbor.net> Mon, 17 July 2017 18:11 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0A2A131CCD for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 11:11:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.92
X-Spam-Level:
X-Spam-Status: No, score=-1.92 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RsXzrnYzS_ai for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 11:11:23 -0700 (PDT)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0116.outbound.protection.outlook.com [104.47.34.116]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 80D86131CCA for <tls@ietf.org>; Mon, 17 Jul 2017 11:11:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=+9MvchGxV+xAW2x3lXu3PatZtHQ/v4/wyTmr7VL4BGs=; b=TzscFBprxxPu3qLZ73kyaBz8/MhidA/ETUECS+wCkrxf0/FtsfNymV8+24LsyFm15qUM5yv5NquGpoRGMqmUTG7k0frvxShzoc25pKeIh56V6rzchUBMxowtyycC1F61Hz4KGiLN53N5mQlZtIYHEYMHawbgkw4zcvD5x+l2FhU=
Received: from DM2PR0101MB1039.prod.exchangelabs.com (10.160.129.156) by DM2PR0101MB1037.prod.exchangelabs.com (10.160.129.154) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 18:11:22 +0000
Received: from DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7]) by DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7%17]) with mapi id 15.01.1261.022; Mon, 17 Jul 2017 18:11:22 +0000
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
CC: IETF TLS <tls@ietf.org>
Thread-Topic: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)
Thread-Index: AQHS/vRnKFRxxE429kKncr36no97/qJX7moAgAANgG2AAAOcAIAABadKgAABXACAAAPrLoAAAY6AgAADO3aAAANXAIAAgtiA//+wwYCAAAwbxA==
Date: Mon, 17 Jul 2017 18:11:22 +0000
Message-ID: <7995AB85-5144-4ABE-993D-EB1415E7E2DD@arbor.net>
References: <CABkgnnU8ho7OZpeF=BfEZWYkt1=3ULjny8hcwvp3nnaCBtbbhQ@mail.gmail.com> <2A9492F7-B5C5-49E5-A663-8255C968978D@arbor.net> <CABkgnnX7w0+iH=uV7LRKnsVokVWpCrF1ZpTNhSXsnZaStJw2cQ@mail.gmail.com> <FDDB46BC-876C-49FC-9DAE-05C61BB5EFC9@vigilsec.com> <9C81BE7B-7C21-4504-B60D-96BA95C3D2FD@arbor.net> <CAEa9xj55jzch-v0mysbRSryNM0Y7Bdtevmrc3+FVxMO8EP5zWA@mail.gmail.com> <CC3CE5F8-C8C2-4A70-829D-483E26D20733@arbor.net> <CAEa9xj5eR6b_+CsSDArMWWr-u8hx5B81kDVEMEX8sgfUeMUS8g@mail.gmail.com> <C3B01C35-E3A2-4A8B-9DD7-D6E4153ED39F@arbor.net> <CAEa9xj6p0y9ZzxLJvtv9GDzzfs5s13nnLqm=4_fNDPGV+=Od8Q@mail.gmail.com> <BE4E8E4A-51FC-4211-A16F-EBA8B3F01757@arbor.net> <66C1C32C-53C2-43A4-BCB0-96DDC26A1F58@ll.mit.edu> <69018030-3157-42D4-A573-0E39E46EFAA9@arbor.net>, <31C01911-5E2B-4812-B4B5-334C7D212F22@ll.mit.edu>
In-Reply-To: <31C01911-5E2B-4812-B4B5-334C7D212F22@ll.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ll.mit.edu; dkim=none (message not signed) header.d=none;ll.mit.edu; dmarc=none action=none header.from=arbor.net;
x-originating-ip: [88.208.89.131]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR0101MB1037; 7:FYkqDWtSwfPVaPljIgE6jRLsBuaQvoCRF/L4X7k+/pcKHwIC+gjNIKphKAmWi+/MTVhEurDXXyiJSvh0SxYiR3fbWb/o8LgIPWkVAwZobEhy/ZLNTTJRKfJHA15ng7x2nFnvW35J02Xq0J3zqLtM7dGCDeg+Z3PGDllNNid+BvRZOYiZUufTfvn2mvpXFTd22we/lvnSlft0nBnyfrPouVXnrPLots+yr/BXUvi+/ncI06GYDeMPrv9uiNlubIcoEQSJ1ikqI+545VcNSXszDz9KmBGNN9fo/tQrqx70axp2EGcMtl5a/NfnxQXcZ+gmkHj47/skJnefZ8UUSfcH/ssRnyryZDEUMZyYRHWSWZHuIv1aHwzCkws6Ygu5l9hsEu2Z0RwI3oCcfbhx/PDQ5ZA54PELk01WU5CJcmocszHPNnh+kF0+8Eq5GO7ZR1bgRviNSOeiEDiMgRqFCEVPOVm/+WzA8qy5ZPtN03tPFoyCIpWCh4VbjkoH/Kw5gWeKeh80lOixojB5e1AjHS1dEmtkFKumcxddXF7hWr1DIT1xYydj6+Zlqz6lhsK3OYX0APYSy7prBx45AZ8BNyG9WFnPYUooY89oewMUyeUHD7QSaXH8sVnArbJM5FmuLQHyHyCAxLtk4GgjZHyZ+LBUR0V93n2Yyy+DLGesLXlhq7geHgq/NO0ZadHOq0KbYK1UKtlMOIEf4U98TgkjQ4wzhA6kgISEreCGYEv2dT6o+8oIrQsNhlBi7gef2ay8Lz+5OwJl85KA3hs7AFo42BPRwcwilnGI4+2Gb//aHlHvdY4=
x-ms-office365-filtering-correlation-id: c92958b2-695a-42ab-6fb7-08d4cd3f3b2b
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1037;
x-ms-traffictypediagnostic: DM2PR0101MB1037:
x-exchange-antispam-report-test: UriScan:(246478575198768)(236129657087228)(192374486261705)(50300203121483);
x-microsoft-antispam-prvs: <DM2PR0101MB103780D062E43B5147C038A9CAA00@DM2PR0101MB1037.prod.exchangelabs.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(2017060910075)(5005006)(10201501046)(3002001)(93006095)(93001095)(100000703101)(100105400095)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123562025)(20161123558100)(20161123560025)(20161123555025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1037; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1037;
x-forefront-prvs: 0371762FE7
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39410400002)(39850400002)(39450400003)(39400400002)(39840400002)(24454002)(2171002)(6246003)(230783001)(50986999)(5660300001)(53936002)(54356999)(76176999)(66066001)(3280700002)(99286003)(36756003)(3660700001)(93886004)(54896002)(6512007)(236005)(2950100002)(6916009)(83716003)(82746002)(14454004)(6506006)(33656002)(6486002)(4326008)(7736002)(81166006)(5250100002)(53546010)(8676002)(189998001)(102836003)(229853002)(25786009)(8936002)(86362001)(2906002)(6436002)(38730400002)(478600001)(6116002)(110136004)(3846002)(2900100001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1037; H:DM2PR0101MB1039.prod.exchangelabs.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_7995AB8551444ABE993DEB1415E7E2DDarbornet_"
MIME-Version: 1.0
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Jul 2017 18:11:22.3387 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 54f11205-d4aa-4809-bd36-0b542199c5b2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1037
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/qkUSpVhR1XqQ9rgqQj0mFtfqQcQ>
Subject: Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 18:11:28 -0000


On Jul 17, 2017, at 19:28, Blumenthal, Uri - 0553 - MITLL <uri@ll.mit.edu<mailto:uri@ll.mit.edu>> wrote:

Organized crime capabilities are reaching the level of nation states, ankle biters reach up to where the organized crime was yesterday…

I understand all this - I have to deal with it every day, so I understand where you're coming from.

But it's also important for understand that security is additive in nature, not all the criminals are bright or sophisticated, & so the emergence of a few smarter ones doesn't make those less so disappear.

In reality, most of them are awful blunderers - they succeed because the defenders are worse blunderers.

Consequently, there hasn't been an alarming (heh) dropoff in the need for TLS visibility on the intranet - quite the opposite.

And the need for it isn't limited to the security space.  It'd extremely important for troubleshooting, as well.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net<mailto:rdobbins@arbor.net>>