Re: Kathleen Moriarty's No Objection on draft-ietf-imapapnd-appendlimit-extension-08: (with COMMENT)
S Moonesamy <[email protected]> Wed, 06 Jan 2016 12:30:43 -0800
| Newsgroups | gmane.ietf.imapext |
|---|---|
| Message-ID | <[email protected]> |
Hi Jay, Naren, At 04:57 06-01-2016, Kathleen Moriarty wrote: > >> The security considerations section doesn't read well IMO. > > > > That's entirely possible. > > > >> When it gets to the following sentence: > >> > >> "But with this extension, the attacker can immediately choose a value > >> that's a little too large," > >> > >> It doesn't read well to me. Why would they chose a value that's a > >> little too large? Too large for what? They already have the size > >> limit per server or per mailbox. Does this mean they will send a > >> bunch of messages with the append size maxed out for the mailbox or > >> the server to fill the quota? > > > > The point of the attack isn't filling a mailbox; it's sending > > boatloads of data to the server. Suppose there's a limit of 2 MB. If > > the client sends 2 MB messages repeatedly, those messages will > > eventually cause the mailbox to hit the quota, and further attempts to > > bombard the server will be rejected. But messages that are, say, > > 2.1MB will fail to append (the server will respond "NO" to them), and > > the client can keep bombarding the server with such messages. The > > text is trying to warn about that, suggesting that the server might > > "take a hard line" -- that is, take more serious action than just > > saying "NO" to the append attempts, but perhaps actually lock out the > > account until someone checks out the situation. > >This point wasn't clear to me from the current text. I'd suggest >updating it to make it more clear. > > > > >> Why isn't it explicit in that such messages should/MUST be rejected? > > > > The messages themselves will be rejected (they APPEND command will get > > "NO" for a response), but the damage -- the sending of a lot of data > > unnecessarily -- will have already been done. > >Can this be made more clear as well? It's not in the current text. Could you please suggest some text to address the above? Regards, S. Moonesamy (as document shepherd) _______________________________________________ imapext mailing list [email protected] https://www.ietf.org/mailman/listinfo/imapext