Re: AD review of draft-ietf-imapapnd-appendlimit-extension-06 (Section 2)

Alexey Melnikov <[email protected]> Fri, 11 Dec 2015 10:30:33 +0000
Newsgroups gmane.ietf.imapext
Message-ID <[email protected]>
On 10/12/2015 23:11, S Moonesamy wrote:
> Hi Jay, Naren,
> At 13:39 10-12-2015, Jayantheesh S B wrote:
>> [Jay]  One advantage I can think of is.
>>  A server can have a customized APPENDLIMIT for different users 
>> (based on some SLA).
>>  The server advertises a static APPENDLIMIT before user logs in, to 
>> display it support for the extension.
>> After user logged in then server can show the user specific APPENDLIMIT.
>>
>>    (ii) What are the disadvantages of advertising the upload limit 
>> before the
>>         user has logged in?
>>
>> [Jay] I don't see any disadvantage in sending the limit before user 
>> logged in.
>
> I'll quote from 
> http://www.ietf.org/mail-archive/web/imapext/current/msg05657.html
>
>   "If the APPENDLIMIT is known beforehand, it's easy to overwhelm 
> server with
>    huge data which is beyond the APPENDLIMIT.  This might facilitate
>    Denial-of-Service attacks.
>    Makes sense?"
>
> Is that as a disadvantage (question (ii))?  Barry asked why that helps 
> anyone mount an attack.  The above reply says that it is easy to 
> overwhelm the IMAP server if the (APPENDLIMIT) value is known 
> beforehand.  Why should the IMAP server advertise the value before the 
> user logs in when it can easily be used to generate an attack?
Well, in order to use this limit, one has to login first (APPEND is 
unavailable in unauthenticated state). And once you are logged in, you 
are allowed to know this limit anyway. So I don't think this makes a 
difference.


_______________________________________________
imapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/imapext