Re: [xmpp] Fwd: I-D Action:draft-miller-3923bis-00.txt

Matthew Miller <mamille2@cisco.com> Tue, 02 March 2010 14:57 UTC

Return-Path: <mamille2@cisco.com>
X-Original-To: xmpp@core3.amsl.com
Delivered-To: xmpp@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 21AB628C0F9 for <xmpp@core3.amsl.com>; Tue, 2 Mar 2010 06:57:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zuqVn89LtDic for <xmpp@core3.amsl.com>; Tue, 2 Mar 2010 06:57:28 -0800 (PST)
Received: from gw2.webex.com (gw2.webex.com [64.68.122.209]) by core3.amsl.com (Postfix) with SMTP id 582E328C0F0 for <xmpp@ietf.org>; Tue, 2 Mar 2010 06:57:28 -0800 (PST)
Received: from SRV-EXSC03.webex.local ([192.168.252.198]) by gw2.webex.com with Microsoft SMTPSVC(6.0.3790.3959); Tue, 2 Mar 2010 06:57:29 -0800
Received: from dhcp-64-101-72-214.cisco.com ([64.101.72.214]) by SRV-EXSC03.webex.local with Microsoft SMTPSVC(6.0.3790.3959); Tue, 2 Mar 2010 06:56:41 -0800
Mime-Version: 1.0 (Apple Message framework v1077)
Content-Type: text/plain; charset="us-ascii"
From: Matthew Miller <mamille2@cisco.com>
In-Reply-To: <8687B872-295A-4976-B2E4-64CF5F2ECBBC@Isode.com>
Date: Tue, 02 Mar 2010 07:57:53 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <A0374BDF-4B5E-4131-973B-2738E480E19B@cisco.com>
References: <4B8C5955.10004@stpeter.im> <8687B872-295A-4976-B2E4-64CF5F2ECBBC@Isode.com>
To: Kurt Zeilenga <Kurt.Zeilenga@Isode.com>
X-Mailer: Apple Mail (2.1077)
X-OriginalArrivalTime: 02 Mar 2010 14:56:41.0130 (UTC) FILETIME=[912FF0A0:01CABA18]
Cc: XMPP <xmpp@ietf.org>
Subject: Re: [xmpp] Fwd: I-D Action:draft-miller-3923bis-00.txt
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Mar 2010 14:58:29 -0000

On Mar 1, 2010, at 20:26, Kurt Zeilenga wrote:

> Peter, Matthew:
> 
> Why are there copies of the time stamp and thread id sent in the clear?
> 
> I would think that having in-the-clear copies would raise some security concerns.
> 

What's not normatively stated is that the visible <thread/> is (SHOULD, MUST?) be different than the encrypted version.  Clients use <thread/>s to note the conversation flow. That said, and now that I've stepped back from it for a while, I see the concern.

We didn't see the timestamp as something to be concerned with, however.
 

> Is there any particular reason why the time stamp inside the object to be signed is simply pre-append to the stanza instead of including it in an element of stanza?

This is how a work-in-progress implementation is doing it, and it so far is proving easy to deal with.  Attempting to embed the timestmap into the stanza will not work with <iq/>-style stanzas, and is the main reason we avoided that.

> 
> Regards, Kurt
> 
> On Mar 1, 2010, at 4:18 PM, Peter Saint-Andre wrote:
> 
>> FYI. This document sketches out an alternate approach to meeting our
>> end-to-end encryption requirements, if only to initiate more discussion
>> about the topic...
>> 
>> /psa
>> 
>> -------- Original Message --------
>> Subject: I-D Action:draft-miller-3923bis-00.txt
>> Date: Mon,  1 Mar 2010 16:15:01 -0800 (PST)
>> From: Internet-Drafts@ietf.org
>> Reply-To: internet-drafts@ietf.org
>> To: i-d-announce@ietf.org
>> 
>> A New Internet-Draft is available from the on-line Internet-Drafts
>> directories.
>> 
>> 	Title           : End-to-End Object Encryption for the Extensible
>> Messaging and Presence Protocol (XMPP)
>> 	Author(s)       : M. Miller, P. Saint-Andre
>> 	Filename        : draft-miller-3923bis-00.txt
>> 	Pages           : 10
>> 	Date            : 2010-03-01
>> 
>> This document defines a method of end-to-end object encryption for
>> the Extensible Messaging and Presence Protocol (XMPP).  The protocol
>> defined herein is a simplified version of the protocol defined in RFC
>> 3923.
>> 
>> A URL for this Internet-Draft is:
>> http://www.ietf.org/internet-drafts/draft-miller-3923bis-00.txt
>> 
>> 
>> _______________________________________________
>> xmpp mailing list
>> xmpp@ietf.org
>> https://www.ietf.org/mailman/listinfo/xmpp
> 
> _______________________________________________
> xmpp mailing list
> xmpp@ietf.org
> https://www.ietf.org/mailman/listinfo/xmpp