Re: AD review of draft-ietf-imapapnd-appendlimit-extension-06 (Section 2)
S Moonesamy <[email protected]> Thu, 10 Dec 2015 15:11:56 -0800
| Newsgroups | gmane.ietf.imapext |
|---|---|
| Message-ID | <[email protected]> |
Hi Jay, Naren,
At 13:39 10-12-2015, Jayantheesh S B wrote:
>[Jay] One advantage I can think of is.
> A server can have a customized APPENDLIMIT for different users
> (based on some SLA).
> The server advertises a static APPENDLIMIT before user logs in, to
> display it support for the extension.
>After user logged in then server can show the user specific APPENDLIMIT.
>
> (ii) What are the disadvantages of advertising the upload limit before the
> user has logged in?
>
>[Jay] I don't see any disadvantage in sending the limit before user logged in.
I'll quote from
http://www.ietf.org/mail-archive/web/imapext/current/msg05657.html
"If the APPENDLIMIT is known beforehand, it's easy to overwhelm server with
huge data which is beyond the APPENDLIMIT. This might facilitate
Denial-of-Service attacks.
Makes sense?"
Is that as a disadvantage (question (ii))? Barry asked why that
helps anyone mount an attack. The above reply says that it is easy
to overwhelm the IMAP server if the (APPENDLIMIT) value is known
beforehand. Why should the IMAP server advertise the value before
the user logs in when it can easily be used to generate an attack?
Regards,
S. Moonesamy (as document shepherd)
_______________________________________________
imapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/imapext