Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00

Hubert Kario <hkario@redhat.com> Thu, 16 October 2014 10:36 UTC

Return-Path: <hkario@redhat.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 06B621ACFC7 for <tls@ietfa.amsl.com>; Thu, 16 Oct 2014 03:36:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.31
X-Spam-Level:
X-Spam-Status: No, score=-0.31 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MANGLED_BACK=2.3, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p_TNiDatkoOF for <tls@ietfa.amsl.com>; Thu, 16 Oct 2014 03:36:12 -0700 (PDT)
Received: from mx5-phx2.redhat.com (mx5-phx2.redhat.com [209.132.183.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB8FB1ACFBC for <tls@ietf.org>; Thu, 16 Oct 2014 03:36:11 -0700 (PDT)
Received: from zmail11.collab.prod.int.phx2.redhat.com (zmail11.collab.prod.int.phx2.redhat.com [10.5.83.13]) by mx5-phx2.redhat.com (8.14.4/8.14.4) with ESMTP id s9GAa7TL019639; Thu, 16 Oct 2014 06:36:07 -0400
Date: Thu, 16 Oct 2014 06:36:07 -0400
From: Hubert Kario <hkario@redhat.com>
To: Bodo Moeller <bmoeller@acm.org>
Message-ID: <95496672.12403991.1413455767572.JavaMail.zimbra@redhat.com>
In-Reply-To: <CADMpkc+P-yRDndj0JK_8tctCHHoL26uBsyX5XRaZa-GPR_aZJQ@mail.gmail.com>
References: <2112FCAD-4820-49D9-9871-6501C83A554D@cisco.com> <543E2D81.1050700@redhat.com> <7F8CB03B-6882-41E7-9705-7126A8F2F44D@gmail.com> <CADMpkcJLrQEtiUGi9B7ZS5402cXTBvvThL9-YwUUhncaXQaVsA@mail.gmail.com> <20141015140158.41a1faf8@pc.my-domain> <CADMpkc+P-yRDndj0JK_8tctCHHoL26uBsyX5XRaZa-GPR_aZJQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_12403990_1800712949.1413455767571"
X-Originating-IP: [10.5.82.7]
X-Mailer: Zimbra 8.0.6_GA_5922 (ZimbraWebClient - FF32 (Linux)/8.0.6_GA_5922)
Thread-Topic: Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
Thread-Index: Zd0q0bIR1BxgFHXKbxGYvuWHoEsJ+A==
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/wrykeXglVsPt1-k8XnzsHON6FT4
Cc: tls@ietf.org
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Oct 2014 10:36:13 -0000

----- Original Message -----

> From: "Bodo Moeller" <bmoeller@acm.org>
> To: tls@ietf.org
> Sent: Wednesday, 15 October, 2014 2:59:59 PM
> Subject: Re: [TLS] Working Group Last Call for
> draft-ietf-tls-downgrade-scsv-00

> Hanno Böck < hanno@hboeck.de > :

> > Can you quantify that tradeoff? How many devices are there really out
> 
> > there that would break? I'd like to have this discussions with
> 
> > hard numbers.
> 

> Finding hard numbers is, well, hard. In general, you find out the whole
> picture about what you've broken only after you've broken it.

> That doesn't mean that people aren't trying to get good estimates (Ivan
> Ristic has done some data collection -- I've include some of his results in
> slide 2 of http://www.ietf.org/proceedings/90/slides/slides-90-tls-0.pdf )

nice 
so ~1% is intolerant to TLS1.1 
~1% is intolerant to 1.2 
and 11% is intolerant to 1.3 (!!) 

were there any servers intolerant to TLS1.0? 

-- 
Regards, 
Hubert Kario