Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Martin Duke TLS Comment 2 #4466

Closed
LPardue opened this issue Dec 29, 2020 · 1 comment · Fixed by #4462
Closed

Martin Duke TLS Comment 2 #4466

LPardue opened this issue Dec 29, 2020 · 1 comment · Fixed by #4462
Labels
-tls iesg An issue raised during IESG review.
Milestone

Comments

@LPardue
Copy link
Member

LPardue commented Dec 29, 2020

@martinduke said:

5.8 says the ODCID field "mitigates an off-path attacker's ability to inject
a Retry".

First, in quic-transport you defined an off-path attacker (21.1) as someone who
can observe but not alter packets. I don't think that's what you mean here, so
please use another a term here or explicitly define what you mean in this
document. Come to think of it, there are some inconsistent usages of this term
in quic-transport as well (14.2.1,17.2.1, 17.2.2 )

Secondly, it is not clear to me what protection this offers beyond the DCID
field in the actual Retry Packet (which corresponds to the SCID of the Initial).

@LPardue LPardue added -tls iesg An issue raised during IESG review. labels Dec 29, 2020
@LPardue LPardue added this to the tls-iesg milestone Dec 29, 2020
@LPardue
Copy link
Member Author

LPardue commented Dec 29, 2020

Proposed resolution is #4462

@LPardue LPardue linked a pull request Dec 29, 2020 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
-tls iesg An issue raised during IESG review.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant