Re: [GNAP] security concerns / issues with data in URLs

Kyle Larose <kyle@agilicus.com> Thu, 19 November 2020 13:12 UTC

Return-Path: <kyle@agilicus.com>
X-Original-To: txauth@ietfa.amsl.com
Delivered-To: txauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BDDBA3A0E51 for <txauth@ietfa.amsl.com>; Thu, 19 Nov 2020 05:12:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=agilicus.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wGhKT5XnMtvk for <txauth@ietfa.amsl.com>; Thu, 19 Nov 2020 05:12:33 -0800 (PST)
Received: from mail-il1-x12d.google.com (mail-il1-x12d.google.com [IPv6:2607:f8b0:4864:20::12d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 458283A0E4F for <txauth@ietf.org>; Thu, 19 Nov 2020 05:12:32 -0800 (PST)
Received: by mail-il1-x12d.google.com with SMTP id q1so5294855ilt.6 for <txauth@ietf.org>; Thu, 19 Nov 2020 05:12:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=agilicus.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=YK93bbzR2De3SaXv1PvcfZAoMdPDWjk5kg1XVEHp9SQ=; b=E/TwbNWbrQ5BFmlD1+XcFbRArmxbvv1Rbpe/VfM+UW6dpT43eIsDhZTPeEWYMbbYYO TC0hR7UFq15hcrWmTzPX5w7epUnnt1QC8Iczo93/m8xojBXq6L/YzFMoKSAAGf5BJzQY 8x8/kZ1C5xShJ/gB4I6PMGCfdd/QncEwFbi40eCnozvbR7An1XccGqZN1dhVK4I0Eqj/ VQbtWGvSXhTde0CrKnXarnS9Ncj5NYtiBWiywcqzPBpBFERpgi7FCNeJ52N6CLhWmrXz 78LwyO+NLnsYwHd1/BLzx3djjrfuSnojH/YbfkaPcF1J0HwjTZ+OEva3ePOK0MfJYffQ WZGw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=YK93bbzR2De3SaXv1PvcfZAoMdPDWjk5kg1XVEHp9SQ=; b=kAGh2G5lzVZLanPJXP8owpey9G7S3FPhWSl4xgIlgaeB+Gi5R9lnN55czz2fJFlYEJ wVylqk824ybhf7RdQPWF8XMbQFB5ToPRzduiMaL7juCrbLO/hBE+Ekuhri+6mBA4OZAb bWx/b5vKrh3GNmxepfxagYUtCIa2mXpwuT8Hu/kteeal39MbX9D5Xvi9DfD4bSZ0rijg gIeGFy9nQHWiunZtWMPrnrb2CpcNSNSR2VX0eGELivWRmNXvpHQL6CDgBbJGZ//PRToh vjY6CsjpZEz0H1p5IZXkI6K5w4MLWrweZ3rtHlVzrlf2bs65Fo5AHLpe9CP7dB3vY83G pWTg==
X-Gm-Message-State: AOAM530D5ZQDgImtXLvb2e35JcvlC6uTmYwHu6mapAbmp84IylPQ91fh U5ED4DM9PgZf4LPqXgDIz2cjm7xCUZOP1b1Y33Z0
X-Google-Smtp-Source: ABdhPJzasAeQ1fwMwc07UDvH/eyNDFNA+eUkVHnzg43US5ANmfoDzrQawezDF5ZTkCNb1qANNOufqDcGOYuKqSQZGR8=
X-Received: by 2002:a92:c7ae:: with SMTP id f14mr5448519ilk.202.1605791551828; Thu, 19 Nov 2020 05:12:31 -0800 (PST)
MIME-Version: 1.0
References: <CAD9ie-v-y+R0Pv3K0KYtVe43AxJ8o89BXZ1vsrVYSJ3SS8Fa=Q@mail.gmail.com> <CAGBSGjpXUrcELkbtXfOvMa+8HTGRs8yyomVu0SoLj+NnXAL+HA@mail.gmail.com> <CAD9ie-vZLhbhDdws8UrJA+_QtU+uA7O+-JEJL9aHQsQPNtNmOA@mail.gmail.com> <4024dc0d-1950-6adf-cd4e-b5299d516fcb@sunet.se>
In-Reply-To: <4024dc0d-1950-6adf-cd4e-b5299d516fcb@sunet.se>
From: Kyle Larose <kyle@agilicus.com>
Date: Thu, 19 Nov 2020 08:12:21 -0500
Message-ID: <CACuvLgyR2W4jn_YWCM240kN+eEFZ1duBNZs=pGskzrmzsBZUZg@mail.gmail.com>
To: Leif Johansson <leifj@sunet.se>
Cc: txauth@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/eocbdRsSruHQDvg0LuIuJDSJs8o>
Subject: Re: [GNAP] security concerns / issues with data in URLs
X-BeenThere: txauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: GNAP <txauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/txauth>, <mailto:txauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/txauth/>
List-Post: <mailto:txauth@ietf.org>
List-Help: <mailto:txauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/txauth>, <mailto:txauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Nov 2020 13:12:35 -0000

On Thu, 19 Nov 2020 at 04:37, Leif Johansson <leifj@sunet.se> wrote:
>
> With my hat off, I heard Aaron say that it helps to keep state out of URLs because
> it reduces the risk that state winds up in logs. Its a practical considaration that
> imo shouldn't be dismissed out of hand.


As an example of where this is likely to happen, many cloud-based
implementations of HTTP services use reverse proxies for load
balancing amongst other things. These often log requests without
understanding the request's intention.