Re: [Unbearable] I-D Action: draft-ietf-tokbind-https-10.txt

Denis <denis.ietf@free.fr> Fri, 21 July 2017 11:03 UTC

Return-Path: <denis.ietf@free.fr>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BA8412EB2B for <unbearable@ietfa.amsl.com>; Fri, 21 Jul 2017 04:03:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.617
X-Spam-Level:
X-Spam-Status: No, score=-2.617 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vrOISbmL6S2J for <unbearable@ietfa.amsl.com>; Fri, 21 Jul 2017 04:03:08 -0700 (PDT)
Received: from smtp6-g21.free.fr (smtp6-g21.free.fr [212.27.42.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 76A6F129B7A for <unbearable@ietf.org>; Fri, 21 Jul 2017 04:03:08 -0700 (PDT)
Received: from [192.168.0.13] (unknown [88.182.125.39]) by smtp6-g21.free.fr (Postfix) with ESMTP id 83A1C7802B2; Fri, 21 Jul 2017 13:03:06 +0200 (CEST)
To: Leif Johansson <leifj@mnt.se>, unbearable@ietf.org
References: <150062800542.11311.4823917490193775849@ietfa.amsl.com> <6029f39a-ea91-a5ae-60cf-d52d0aeeb718@free.fr> <CACdeXi+gPpAvRuPsTgQte8ugmePUra5QLO2N0gHzkE9MKLjy2A@mail.gmail.com> <733401bb-4204-ebfb-1e4d-49c70eec2604@free.fr> <c132c588-3e5e-9004-8ba3-ebed325c08a5@mnt.se>
From: Denis <denis.ietf@free.fr>
Message-ID: <727870d8-4bb0-b465-9fe5-005073d6c4f1@free.fr>
Date: Fri, 21 Jul 2017 13:03:06 +0200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <c132c588-3e5e-9004-8ba3-ebed325c08a5@mnt.se>
Content-Type: multipart/alternative; boundary="------------18870F998F957F45BB8FEB21"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/kCW6MX2hSnn8hp1VmcnB7WLH5-o>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-https-10.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Jul 2017 11:03:10 -0000

Leif,

The text that was quoted is in the Security Considerations section under 
section "7.1.  Security Token Replay"
from draft-ietf-tokbind-protocol.

I already said on the list that the text does not fit under section 7.1 
since it is not a security token *replay* in any sense,
since the legitimate client is not playing anything, so it cant' be a 
replay.

It should be under a specific section called, e.g.: Client collusion.

It is particularly important that readers realize that this protection 
is not effective under some circumstances.

Is there any harm to warn the user in both documents  ?

Denis

>
> On 2017-07-21 11:40, Denis wrote:
>> Nick,
>>
>> A person reading draft-ietf-tokbind-https will not necessarily also read
>> draft-ietf-tokbind-protocol.
> Since there is text in draft-ietf-tokbind-https with normative
> references to draft-ietf-tokbind-protocol I don't believe that
> is a reasonable assumption.
>
> 	Cheers Leif
>
> _______________________________________________
> Unbearable mailing list
> Unbearable@ietf.org
> https://www.ietf.org/mailman/listinfo/unbearable