Last Call Review of draft-koster-rep-10
review-koster-rep-10-secdir-lc-reddyk-2022-06-24-00
| Request | Review of | draft-koster-rep |
|---|---|---|
| Requested revision | No specific revision (document currently at 12) | |
| Type | IETF Last Call Review | |
| Team | Security Area Directorate (secdir) | |
| Deadline | 2022-04-07 | |
| Requested | 2022-02-28 | |
| Authors | Martijn Koster , Gary Illyes , Henner Zeller , Lizzi Sassman | |
| I-D last updated | 2022-09-12 (Latest revision 2022-07-06) | |
| Completed reviews |
Secdir IETF Last Call review of -10
by Tirumaleswar Reddy.K
(diff)
Artart IETF Last Call review of -06 by Todd Herr (diff) Artart IETF Last Call review of -08 by Todd Herr (diff) Intdir IETF Last Call review of -08 by Ralf Weber (diff) |
|
| Assignment | Reviewer | Tirumaleswar Reddy.K |
| State | Completed | |
| Request | IETF Last Call review on draft-koster-rep by Security Area Directorate Assigned | |
| Posted at | https://mailarchive.ietf.org/arch/msg/secdir/0LN8eLWJ2t03m7HCDD1FXAqy5xA | |
| Reviewed revision | 10 (document currently at 12) | |
| Result | Has issues | |
| Completed | 2022-06-20 |
review-koster-rep-10-secdir-lc-reddyk-2022-06-24-00
SECDIR Review draft-koster-rep Reviewer: Tirumaleswar Reddy Review result: Ready with Issues I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.. Document editors and WG chairs should treat these comments just like any other last call comments. You may want to discuss the following security threats: a) Revealing disallowed URIs will make its paths easily discoverable. However, security by obscurity will not maintain or increase the security of the content provider (you can refer to https://datatracker.ietf.org/doc/html/rfc4949). b) A malicious crawler will not honor the disallow rules and can try to access the disallowed URIs, it should be mitigated by access control restrictions. Discuss any other count-measures used to block such malicious crawlers (like blocking the IP address). c) Attacks possible on crawlers because of a malicious robots.txt file. Cheers, -Tiru