
From nobody Mon Feb  1 04:47:22 2016
Return-Path: <fanf2@hermes.cam.ac.uk>
X-Original-To: shutup@ietfa.amsl.com
Delivered-To: shutup@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 086871A0049; Mon,  1 Feb 2016 04:47:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.502
X-Spam-Level: 
X-Spam-Status: No, score=-1.502 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MZyMx1UyZSkH; Mon,  1 Feb 2016 04:47:18 -0800 (PST)
Received: from ppsw-33.csi.cam.ac.uk (ppsw-33.csi.cam.ac.uk [131.111.8.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9E3891A0032; Mon,  1 Feb 2016 04:47:18 -0800 (PST)
X-Cam-AntiVirus: no malware found
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from hermes-2.csi.cam.ac.uk ([131.111.8.54]:44761) by ppsw-33.csi.cam.ac.uk (smtp.hermes.cam.ac.uk [131.111.8.157]:25) with esmtpa (EXTERNAL:fanf2) id 1aQDsv-0005Nu-fz (Exim 4.86_36-e07b163) (return-path <fanf2@hermes.cam.ac.uk>); Mon, 01 Feb 2016 12:47:13 +0000
Received: from fanf2 by hermes-2.csi.cam.ac.uk (hermes.cam.ac.uk) with local id 1aQDsu-00076V-Vl (Exim 4.72) (return-path <fanf2@hermes.cam.ac.uk>); Mon, 01 Feb 2016 12:47:12 +0000
Date: Mon, 1 Feb 2016 12:47:12 +0000
From: Tony Finch <dot@dotat.at>
X-X-Sender: fanf2@hermes-2.csi.cam.ac.uk
To: "Carl S. Gutekunst" <csg@alameth.org>
In-Reply-To: <56ABD3DA.70203@alameth.org>
Message-ID: <alpine.LSU.2.00.1602011244480.11434@hermes-2.csi.cam.ac.uk>
References: <20160129180713.51570.qmail@ary.lan> <56ABD3DA.70203@alameth.org>
User-Agent: Alpine 2.00 (LSU 1167 2008-08-23)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: Tony Finch <fanf2@hermes.cam.ac.uk>
Archived-At: <http://mailarchive.ietf.org/arch/msg/shutup/algx4_g5BveOvyKqu93ncknGWfE>
Cc: shutup@ietf.org, John Levine <johnl@taugh.com>, ietf-smtp@ietf.org
Subject: Re: [Shutup] [ietf-smtp] Compressing SMTP streams
X-BeenThere: shutup@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMTP Headers Unhealthy To User Privacy <shutup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/shutup>, <mailto:shutup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/shutup/>
List-Post: <mailto:shutup@ietf.org>
List-Help: <mailto:shutup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shutup>, <mailto:shutup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2016 12:47:20 -0000

Carl S. Gutekunst <csg@alameth.org> wrote:
>
> We assume that binary MIME (ala RFC 3030) is dead.

BURL is designed to work with BDAT, so that you can submit a message in
chunks with verbatim parts (BDAT) and out-of-line attachments (BURL).

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  http://dotat.at/
Fair Isle, Faeroes, Southeast Iceland: Cyclonic gale 8 to storm 10, decreasing
5 to 7 at times. Very rough or high, becoming very high for a time. Rain or
squally showers. Poor, occasionally good.


From nobody Sat Feb  6 02:16:06 2016
Return-Path: <azet@azet.org>
X-Original-To: shutup@ietfa.amsl.com
Delivered-To: shutup@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B0EEF1B2A5E for <shutup@ietfa.amsl.com>; Sat,  6 Feb 2016 02:16:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sy4HUbzfLGe6 for <shutup@ietfa.amsl.com>; Sat,  6 Feb 2016 02:16:04 -0800 (PST)
Received: from mail-wm0-x22b.google.com (mail-wm0-x22b.google.com [IPv6:2a00:1450:400c:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 037FA1B2A5C for <shutup@ietf.org>; Sat,  6 Feb 2016 02:16:04 -0800 (PST)
Received: by mail-wm0-x22b.google.com with SMTP id p63so56501392wmp.1 for <shutup@ietf.org>; Sat, 06 Feb 2016 02:16:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=azet.org; s=gmail; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to; bh=HINgk40U0ujso2EZaYo9H2oEl9IZQbgnMf1nJDSWNx8=; b=b0Z3Ys0xpFmID8D+o/uNN8KXf6H3zhu81BjqjvIYf8GIYa3/br8q7pj3vpf9lHA4Oh 3AQMjyX4LLLLu4Fxxg5npjx/n1X42Hdqj/QqxYFAHE8hIDpi6gGRxD3Elxxk2KUQGGaB bq3WP6cH7nlkXmiCVosheqjK9H0KMtKHvTHIQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:mime-version:content-type:from :in-reply-to:date:cc:message-id:references:to; bh=HINgk40U0ujso2EZaYo9H2oEl9IZQbgnMf1nJDSWNx8=; b=BSfXRKcrTv0CWGo3cCp9vKPCfEIJCJ8cM/5S45S0Mvs5Iv/+38Ykc1JwCIVFrscvyl NP7RWXDd206in7zweHowFvwcjr7waqOpEC29mS3IA54RUEJ0JSOzMgbYCRFTuCrC6cMb E5tD5sHYSaRRXwkJPb+5Z9GnaFrI8xkdhqai74fdfAQ7sxtaN6n1cwTftuj/tVyvh/Ud /6JQUNUnPYhmat7mvnn1steq/b1TxSk0ZuZEJNhMOyOebOusO5fV2qYJ/thRF/rqA8vv 2p7dMXzDeFfqA1i+KIGmkYBNmHtP39TmpsssnaEmKD0G1gJBd+ycVbkezhOHzNaXf/gU a3Uw==
X-Gm-Message-State: AG10YOQ7BzDlm4/9mBSZUlE/2Ja3lrkv+IYKwHSth3crSt4VSs0EKzbW35DONUgHEAoeKw==
X-Received: by 10.28.22.201 with SMTP id 192mr22471468wmw.1.1454753762556; Sat, 06 Feb 2016 02:16:02 -0800 (PST)
Received: from [100.65.68.6] ([147.229.63.131]) by smtp.gmail.com with ESMTPSA id i1sm4773568wjs.45.2016.02.06.02.15.59 (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sat, 06 Feb 2016 02:16:01 -0800 (PST)
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
Content-Type: multipart/signed; boundary="Apple-Mail=_64A7A392-F2C4-4D3E-AA9C-8A21A8531024"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.6b2
From: Aaron Zauner <azet@azet.org>
In-Reply-To: <20160129180713.51570.qmail@ary.lan>
Date: Sat, 6 Feb 2016 11:15:54 +0100
Message-Id: <E89BE40D-6635-4581-B2B7-13F2D5190CB2@azet.org>
References: <20160129180713.51570.qmail@ary.lan>
To: John Levine <johnl@taugh.com>
X-Mailer: Apple Mail (2.3112)
Archived-At: <http://mailarchive.ietf.org/arch/msg/shutup/XJpVdnz7XZT7JhC8-LdNR2JCqfA>
Cc: csg@alameth.org, shutup@ietf.org, ietf-smtp@ietf.org
Subject: Re: [Shutup] [ietf-smtp] Compressing SMTP streams
X-BeenThere: shutup@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMTP Headers Unhealthy To User Privacy <shutup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/shutup>, <mailto:shutup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/shutup/>
List-Post: <mailto:shutup@ietf.org>
List-Help: <mailto:shutup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shutup>, <mailto:shutup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Feb 2016 10:16:05 -0000

--Apple-Mail=_64A7A392-F2C4-4D3E-AA9C-8A21A8531024
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hi,

> On 29 Jan 2016, at 19:07, John Levine <johnl@taugh.com> wrote:
>=20
>> Compression has been removed completely from TLS v1.3, the outcome of
>> the room consensus at IETF-89.
>=20
> Bummer.

No, it's a security *feature*.

>=20
> Well, in that case, here's a straw man proposal.
>=20
> The extension name is COMPRESS, the EHLO keyword is COMPRESS and is
> followed by a space-separated list of compression schemes, currently
> consisting only of DEFLATE (RFC 1951.)
>=20
> There's one new command, COMPRESS which takes as an argument the type
> of compression to be used.  If you want to do both STARTTLS and
> COMPRESS, the results of doing COMPRESS before STARTTLS are
> aggessively undefined.
>=20
> The responses to COMPRESS are:
>=20
> 500 compress not supported
> 501 compression scheme unknown
> 220 go ahead

I'm strongly opposed to this.

Do you guys have any numbers on this? I.e. what the advantage and =
compression ratio for your average mail traffic will be? I suspect =
compression is helpful in SMTP but it may also introduce vulnerabilities =
in combination with TLS. CRIME wasn't the only attack on compression, =
there's also been application layer specific attacks - BREACH for =
example (breachattack.com). A team is currently working on improving =
these attacks in application layer protocols, circumvent =
counter-measures in clients et cetera (from a talk at =
RealWorldCrypto2016 - =
https://drive.google.com/file/d/0Bzm_4XrWnl5zMkJJdHo0Rml4bXM/view?usp=3Dsh=
aring).

Another problem with SMTP extensions is that mail daemons are rarely =
updated thus it takes quite some years to have real support on the =
internet.

Aaron

--Apple-Mail=_64A7A392-F2C4-4D3E-AA9C-8A21A8531024
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJWtcfaAAoJEOTbZJL9ubXVWLcQAIBy8alBgyENul2eMkbm81no
E3zFsRuuikdiSnfZiv2mfJU8eexqxXJfF784APpjF+RRjFwAgkrNo1XWXDkKEiQI
tzQYQz4HSu2hSOJFFK3p25S0dhWgqFx2Sm0qzy6/zdBsXl6iyTUlpatnhAmuovpM
nKWlg1u/CO4BazuGJbDMsF1CEII/bET9HELeDzv7lBKJpDdNQqpa3CLZl208bWRY
mR7BLliW27Rrf9yzwgO/EinAKtFan/N3xweiz3gstqLgdBZv0IXbR8mBKjdyCmWo
MwaV026xUXnWKBya985XgrEdJgslKjrWhtiWV0YNUnxW0PWFqQANmh5+sgr2MuyN
ydotNlzf6R73VDFccn5lzAj0K7/lT0VzNJQtU6R+zZp3Rzs2ksmNt31mHq6QdLnQ
vcU0LOuWABHUYhNuU/8Os4mMVOXZJdJdkdNJnlxjD1nt/UnqM1KwtFWZR8dqB8RD
xxeqdK8xZqePlltIZNJ9o1lwCvRxRvc3/hrQMtR0OBUw2GoR9NInwjQVAgjzjye8
Gj1iKoDam/mxNfwIOpIwEDasvJNC2w5vr5xPh1ihGrf45mGabwNWd3Vd6a4t+/3N
ERVqVJ7o3wa4ww4mj64Na4Dk+QeIQPr2Doy2S+hSkLzY6W50G//AsV3ZF+PFSNJs
8MdhZMAdC6eb04i1yTM0
=nsdT
-----END PGP SIGNATURE-----

--Apple-Mail=_64A7A392-F2C4-4D3E-AA9C-8A21A8531024--


From nobody Sat Feb  6 03:32:34 2016
Return-Path: <martijn@lapsedordinary.net>
X-Original-To: shutup@ietfa.amsl.com
Delivered-To: shutup@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E13F31B2C2A; Sat,  6 Feb 2016 03:32:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.079
X-Spam-Level: 
X-Spam-Status: No, score=-1.079 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HELO_MISMATCH_NET=0.611, HOST_MISMATCH_COM=0.311, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id usB1ZhPwk1C3; Sat,  6 Feb 2016 03:32:30 -0800 (PST)
Received: from mail.lapsedordinary.net (thinksmall.vps.bitfolk.com [85.119.83.85]) by ietfa.amsl.com (Postfix) with ESMTP id 6DFC21B2C2E; Sat,  6 Feb 2016 03:32:30 -0800 (PST)
Received: by mail.lapsedordinary.net (Postfix, from userid 1000) id D5C3B34063; Sat,  6 Feb 2016 11:32:26 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=lapsedordinary.net; s=mail; t=1454758346; bh=JJ+tE3Mn1sKr3Q2mu+DJiHq1C5IQNe2Kuk62/s9sTCY=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:In-Reply-To; b=nwl3WFYdyu3hbxt1vr6UJSY4V915oW8bKa+KUC0X2KEG/ITyU7GUOecvmnpfgh5hI ZoQZtNKaziBfl/gNXq5pdWXKyfTaObkUkC1dkpYoWmbgD8y11mXwsydo1HIyyg1WER +plL9w+AuZKfPGzcCnjzYq4SA3sJm9dsIS/lyaiQ=
Date: Sat, 6 Feb 2016 11:32:26 +0000
From: Martijn Grooten <martijn@lapsedordinary.net>
To: shutup@ietf.org
Message-ID: <20160206113226.GA21279@lapsedordinary.net>
References: <20160129180713.51570.qmail@ary.lan> <E89BE40D-6635-4581-B2B7-13F2D5190CB2@azet.org>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="liOOAslEiF7prFVr"
Content-Disposition: inline
In-Reply-To: <E89BE40D-6635-4581-B2B7-13F2D5190CB2@azet.org>
User-Agent: Mutt/1.5.20 (2009-06-14)
Archived-At: <http://mailarchive.ietf.org/arch/msg/shutup/t4RNuu8uWTGuWhlT5wXR6eyAvPE>
Cc: ietf-smtp@ietf.org
Subject: Re: [Shutup] [ietf-smtp] Compressing SMTP streams
X-BeenThere: shutup@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMTP Headers Unhealthy To User Privacy <shutup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/shutup>, <mailto:shutup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/shutup/>
List-Post: <mailto:shutup@ietf.org>
List-Help: <mailto:shutup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shutup>, <mailto:shutup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Feb 2016 11:32:32 -0000

--liOOAslEiF7prFVr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Feb 06, 2016 at 11:15:54AM +0100, Aaron Zauner wrote:
> Do you guys have any numbers on this? I.e. what the advantage and
> compression ratio for your average mail traffic will be? I suspect
> compression is helpful in SMTP but it may also introduce
> vulnerabilities in combination with TLS. CRIME wasn't the only attack
> on compression, there's also been application layer specific attacks
> BREACH for example (breachattack.com). A team is currently working on
> improving these attacks in application layer protocols, circumvent
> counter-measures in clients et cetera (from a talk at            =20
> RealWorldCrypto2016 -
> https://drive.google.com/file/d/0Bzm_4XrWnl5zMkJJdHo0Rml4bXM/view?usp=3Ds=
haring).                                                                   =
                                                                           =
                           =20

I think it's fair to say (as others have done already) that none of
these attacks work against SMTP as they all require the attacker to
force the client to make specific requests to the target.

But these attacks also show that compression and encryption don't go
well together. And crypto is hard and provides plenty of opportunities
to mess up. For that reason, I would suggest following TLS 1.3 and not
combine the two, as it would teach people bad habits.

Martijn.


--liOOAslEiF7prFVr
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJWtdnKAAoJEI5dMs9dIv8ZelcH/0LIxYBPep70HZtzU4r3rL/y
C78R0aG52J011Dcx1dyjfFt25zfvFvAwamYOh1gztc/g15BZCvVEtal3kAM6L4Rv
IT4iNUOp5ByBxU3pcUak1ZnciNz4wo9MMoUXh7QznWrfyJjxEOVpXq8bUA4S4thR
aABlPaPRHEgAvevz9vHmutmNqGIH8NVNaHd0vdlVKwAt6FRe2tQeQihqxR78L3Ip
xJb3u4dg5rLdkh7iHWE45xI1KVtW8Pl/bX9R4KB4OT5vv0QhmBiSUz0dTi/c6s8Y
NVZt6CB3CGyzkMkTZ3y9p+zKJaWk/xrRGZRxMIyeVjSQYnFu/avak3FiQroyQ/8=
=iSVn
-----END PGP SIGNATURE-----

--liOOAslEiF7prFVr--


From nobody Sat Feb  6 03:40:36 2016
Return-Path: <azet@azet.org>
X-Original-To: shutup@ietfa.amsl.com
Delivered-To: shutup@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C894D1B2C6D for <shutup@ietfa.amsl.com>; Sat,  6 Feb 2016 03:40:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LwORiqEn9H2R for <shutup@ietfa.amsl.com>; Sat,  6 Feb 2016 03:40:33 -0800 (PST)
Received: from mail-wm0-x234.google.com (mail-wm0-x234.google.com [IPv6:2a00:1450:400c:c09::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B185C1B2C6B for <shutup@ietf.org>; Sat,  6 Feb 2016 03:40:32 -0800 (PST)
Received: by mail-wm0-x234.google.com with SMTP id 128so101219970wmz.1 for <shutup@ietf.org>; Sat, 06 Feb 2016 03:40:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=azet.org; s=gmail; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to; bh=bPlLjg9r6EGhhbzzTT6A9nb9DYcRG91RUa/dzTKGMdU=; b=OCNckXqd1YwQlUSfITtHViKhaH2kpBJLUkeFCZPsR8nw0YhvApss7c59Gf1j0bhoow jH4LRrjRq+MqAQz86PIX//sCHGPmz2aAP+x0qhOrYPw4uxoO+FhXih/FkCbVBRXO+YyV 4I8irw0WgWog8p/YE3BW4cZQTFBwbiP9g8XIk=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:mime-version:content-type:from :in-reply-to:date:cc:message-id:references:to; bh=bPlLjg9r6EGhhbzzTT6A9nb9DYcRG91RUa/dzTKGMdU=; b=FC8EX+LniLzgNAGfhyI5lOqvbtAADaCHu1Pa+bWrVUipPlyw8kZt+EX6tlscw0h6xX UTYaAQbScOQq0mYuD9bXDTz4HNDBxQfwaLcK8vbanzQ9UAgJRat7r4p621Lv51Pc6fr0 n8Fde670VbqirY8n8bGm/vAUq8+P4IDdCklQR4S11rLQuqeU6Ux33ImrvjuON+FmQpLX A/0+1vclhjKI7A7COuzHlK12l3YJS/9N/d9vXMUEeKA+6hRMYEI7LGZ0tuHseEWvJgjd pCreWoAL0WTyLIX5MuZ1m1XBOmEEZMb1lzIrDWAaYJcrj+IDcT5O2MIvqNXjRwkWIcBG R9iQ==
X-Gm-Message-State: AG10YOQU+YtTvUc1IelxZ65SZdM6+pxX0cXz6h24LQAuVHKmBLSwfk3h5Oxogkpx6aIqxw==
X-Received: by 10.194.19.164 with SMTP id g4mr18510624wje.120.1454758831290; Sat, 06 Feb 2016 03:40:31 -0800 (PST)
Received: from [100.65.68.6] ([147.229.63.131]) by smtp.gmail.com with ESMTPSA id jc7sm20055125wjb.33.2016.02.06.03.40.28 (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sat, 06 Feb 2016 03:40:29 -0800 (PST)
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
Content-Type: multipart/signed; boundary="Apple-Mail=_9705DC50-5026-4971-80E7-1DE0F96F0F49"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.6b2
From: Aaron Zauner <azet@azet.org>
In-Reply-To: <20160206113226.GA21279@lapsedordinary.net>
Date: Sat, 6 Feb 2016 12:40:21 +0100
Message-Id: <063A8F81-2BEE-4006-8D2D-002228379C82@azet.org>
References: <20160129180713.51570.qmail@ary.lan> <E89BE40D-6635-4581-B2B7-13F2D5190CB2@azet.org> <20160206113226.GA21279@lapsedordinary.net>
To: Martijn Grooten <martijn@lapsedordinary.net>
X-Mailer: Apple Mail (2.3112)
Archived-At: <http://mailarchive.ietf.org/arch/msg/shutup/lPyVRYrgCxtnCSGB3EsXmk7DYNI>
Cc: shutup@ietf.org, ietf-smtp@ietf.org
Subject: Re: [Shutup] [ietf-smtp] Compressing SMTP streams
X-BeenThere: shutup@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMTP Headers Unhealthy To User Privacy <shutup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/shutup>, <mailto:shutup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/shutup/>
List-Post: <mailto:shutup@ietf.org>
List-Help: <mailto:shutup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shutup>, <mailto:shutup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Feb 2016 11:40:34 -0000

--Apple-Mail=_9705DC50-5026-4971-80E7-1DE0F96F0F49
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


> On 06 Feb 2016, at 12:32, Martijn Grooten <martijn@lapsedordinary.net> =
wrote:
>=20
> On Sat, Feb 06, 2016 at 11:15:54AM +0100, Aaron Zauner wrote:
>> Do you guys have any numbers on this? I.e. what the advantage and
>> compression ratio for your average mail traffic will be? I suspect
>> compression is helpful in SMTP but it may also introduce
>> vulnerabilities in combination with TLS. CRIME wasn't the only attack
>> on compression, there's also been application layer specific attacks
>> BREACH for example (breachattack.com). A team is currently working on
>> improving these attacks in application layer protocols, circumvent
>> counter-measures in clients et cetera (from a talk at
>> RealWorldCrypto2016 -
>> =
https://drive.google.com/file/d/0Bzm_4XrWnl5zMkJJdHo0Rml4bXM/view?usp=3Dsh=
aring).
>=20
> I think it's fair to say (as others have done already) that none of
> these attacks work against SMTP as they all require the attacker to
> force the client to make specific requests to the target.

Well, yes. You just can't do JavaScript via SMTP (yet) :)

> But these attacks also show that compression and encryption don't go
> well together. And crypto is hard and provides plenty of opportunities
> to mess up. For that reason, I would suggest following TLS 1.3 and not
> combine the two, as it would teach people bad habits.

There aren't that many people looking into this, with renewed research =
efforts I fear that these attacks may improve significantly. The authors =
of mentioned work on improving these attacks explicitly mentioned other =
application layer protocols than HTTP(S) in the Q/A after the talk. They =
will also be presenting new attacks at upcoming conferences. As I see it =
- adding compression might reduce traffic load for some providers but at =
the same time may introduce new vulnerabilities in the future to already =
poorly-secured protocols like SMTP.

Aaron

--Apple-Mail=_9705DC50-5026-4971-80E7-1DE0F96F0F49
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJWtdumAAoJEOTbZJL9ubXVffsQAKwNRx0dKkymzzK5x5Gkiqge
Z05dpIps3nF4p6E4gU1QSIGLxDuksxvXmr9nt9iUV+Aklqz/ULifJFhVdf3Obgpt
GS5bHBFJGGXh0H7xmLl24fX+sxM9CZwI8qDudooEak16R0yEVDCMEe5ZLw9YAO4A
VYiLO2pfPVuLgOr1F/NVjJCuqsl1doC9bXw9e2AdqNPNcTTg+y2WmHutQCqVWnvz
YHP35JggrCovgUmIfVEmJAidoTCZ8koWPh6UMwUFw7bPWdJbz6ozfRWykv5ibNKQ
+ANVMcqbqZhg9oDDyAQY9j3EQh0nEm3DigBKLNIpWZVDQgYKG0CMgo7zwFKfFA2U
YVy8v/CSrMRu7frEfY935LaHfrpZ6Duxsnjr38vbNShOjAlG6zuSFIJEk8qngIqI
50+lmYD9nnUs2WWVQgPlvOKx04xxXUGMKlSc3lGbHikp5j/23WuL6rxuWiAojbGM
ZS9UZEE0efjvtYbPIu/dsuqaB3wGvUGVOWr7eoP5HpE6hpWRizUMe8QQJraoXpEU
M8n0bAnq2tCYyDul350Di6taYzva0Os4mEiRu/prMeaQvE1MGsjE+oG2x938ySwQ
SkpYAaJ01oMwZLwtzkGcGRUzRapoRwxWTgwyzmJagOahWkdmwMIlN/Jd1ajyUYAT
fj3fQuxZlAAlX7W50QTr
=04gN
-----END PGP SIGNATURE-----

--Apple-Mail=_9705DC50-5026-4971-80E7-1DE0F96F0F49--

