Re: [111attendees] Why do we allow people to edit CodiMD meeting notes who are not logged in?

Stephen Farrell <stephen.farrell@cs.tcd.ie> Sun, 01 August 2021 20:23 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: 111attendees@ietfa.amsl.com
Delivered-To: 111attendees@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C18733A0D6E; Sun, 1 Aug 2021 13:23:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N4c3tQGewHZK; Sun, 1 Aug 2021 13:23:08 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2139.outbound.protection.outlook.com [40.107.22.139]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67F3F3A0D6B; Sun, 1 Aug 2021 13:23:08 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bFAwKRYHjYfHgZnmiVFZvElSuB+jkMDuK67ufX5XJZOGdbZ85rIvhXj9wwgM7+Fqu6arWBRn/ye3z06GFcywknXLeqU0aduzQgwsusENgvdZ/NPwtAZQ2KPPOSjRlW6jpdIiPyNrYiIwF/bp66v7b8t3ctKECZ6hS5akAjdp73BNLwQE83chyVcaxBt3Iyln9vOdy3d1AFUuv0jzwOJ8FEH1/IXMf6ofQxpyyNprDYnkRHHxQk2EVJvmWwhqsspE0HHG54R66W/9iuvB2+KHG1RhKknc+4tEjIM2aX81MqZbHGI1I5PypwLQcGGXX4IWd1oWSot0pPj5f2SMJBwAvQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kH+TqWDEAim7JM4UelgYjWQs/rHqbsnyBrA+M8U8eCo=; b=hs66Ry84igmAdwoGHiewALTO3JuvIMAFrsnj5IGTu3k21L+iHQDpp9N95mp93n3FGaibzAFxPHKtzwMKxwZfRPRL8tQHi/ex+8TplJxiQ6DHBHDttDwO9STZBUWoDvXodqWoRo0Px12xcFMqtDW9+dymLBa3XKykSnYPcbMv0eWkt5So8tfUdEUswnIjaXO2QkZG8u48quZZBIz8WdSKGs0LC0KuCuJrHULq+O+KYdv8cYrhHhUGHa2ccFGNdLsuSaxPCfFlnUFS3fiq9ha5g0flRuandDzmsZM2VZUaes2BWFhwavDBskQHmuOKZPGmowBJCEk7LJkSGdq96OwlKg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kH+TqWDEAim7JM4UelgYjWQs/rHqbsnyBrA+M8U8eCo=; b=Yy6WcntMdMIVMMnpWQXHpgLNgfY4SxSFhWvr3hxHErGSEi3Y/eFgz8goUOw1M6v2AC3JRsL7PQSUOiL8SW9l7qGh5T4qVifaWtkbU58bIX5PFQAGsco4iQjLqnOvypf0UQRQRn8YeCxmiUVWcv8MgmsyOUiLY5gu15SA8F4KwgaRDUZzp9hkHW3bxjE3fk7aEFn2+3ceGMquBYicieSJAYJ7zQPYboJAcv6Mn26TBSyo8hTz7zXE27oMtoQAnN4IcTPB/DADFhwj/l1jpydyfsHTKIuFB3P//zfjXNXomVhUGEdrOT+AMGPnL8kN6JOoja89pDZXGUvtEsfD2Ct7gg==
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by DB9PR02MB6779.eurprd02.prod.outlook.com (2603:10a6:10:1f8::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.21; Sun, 1 Aug 2021 20:23:02 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::4198:a9d1:7246:8272]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::4198:a9d1:7246:8272%3]) with mapi id 15.20.4373.026; Sun, 1 Aug 2021 20:23:02 +0000
To: Carsten Bormann <cabo@tzi.org>, Tools Discussion <tools-discuss@ietf.org>
Cc: "111attendees@ietf.org" <111attendees@ietf.org>
References: <8a1018d3-62da-a740-72d6-bb370af71a9e@joelhalpern.com> <20210731193455.C04E625657CF@ary.qy> <7A01A718-246F-4DFD-B522-EC4D7C945199@akamai.com> <72755DA5-56E8-4DF9-A2B6-2BBDD315094A@tzi.org>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Message-ID: <daaf0898-fcaf-341b-a710-9c459edebdc1@cs.tcd.ie>
Date: Sun, 01 Aug 2021 21:23:00 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0
In-Reply-To: <72755DA5-56E8-4DF9-A2B6-2BBDD315094A@tzi.org>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="QG0pwmoA2zGhoG0IUhsjgMIWLx8KxYAYA"
X-ClientProxiedBy: DBBPR09CA0036.eurprd09.prod.outlook.com (2603:10a6:10:d4::24) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [10.244.2.119] (95.45.153.252) by DBBPR09CA0036.eurprd09.prod.outlook.com (2603:10a6:10:d4::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.18 via Frontend Transport; Sun, 1 Aug 2021 20:23:02 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: fe447462-dcf2-40fc-8ae9-08d9552a298d
X-MS-TrafficTypeDiagnostic: DB9PR02MB6779:
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-Microsoft-Antispam-PRVS: <DB9PR02MB6779ACE5CAF9E8D2991E43E4A8EE9@DB9PR02MB6779.eurprd02.prod.outlook.com>
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Oob-TLC-OOBClassifiers: OLM:741;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: ztnojvtQcO4xlR8t3Pplo329Bjz1csXocQfadUj6fHkjz/HoyOG4KU6nmKlybanVaTRPuMjC6DMU4Advxcyor4JYRQWFbVdzhjNRE9757CRxpgkiDgks33ccZTdDWSbxl/kkg601fGmy8KuUyFotr8Y9dlsyRxTFkY5XB3rufnRKWNFsRR1DnHUOFF0V2lvaEhQL2/EsfoHaMKAtth61GK+rF5bpC8XurfGNyDCrL25jad+hTylB+ivnC3rR4Gne/jpzJT3xWu4Xln5FwiOTJsDt1knHrvENfsRiCH3+osE+heuf5l10sx5JkHQ10H9twVUWAdcYP7A33YI/iG4Eb63WCAQnFhPsjxWQyLFlxavKtmX0LjjhGu+mZLokSUDWoaFIvpZst2tZhs9CfHBmp4twbRLgQMVv4dAeqnvJi9VaqG0o9ErCW0wryHcfEUvRXeaq1lISf+DYnq/Li/BvTPYnhrVwbSi3zdNtGJ4m9Z6oZmdOPNxa61vFVAcfPxNERF7vIwg8kEnGrErExZVA1QHUaDCaT0WGftmyGhsxAE7dLmOu4OQEQpZmWJyZOgvl3q64TjsllmR3FqRQ6DTXqM86b3j0ssf3Mfmu/n4iD9cjrkLIgumDwS34jioHOFUuxkBNNjZgxEgvUd943W+8wh2ew2PYy02+Gm7BeGIz/V1SIvVbJ+J5KbejCy8YILRTqavmSpllAFeDggapPPRFd7pLet8PouycbgePjOTD7CI=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(316002)(786003)(16576012)(508600001)(2616005)(956004)(8676002)(8936002)(2906002)(38100700002)(26005)(31686004)(110136005)(21480400003)(6486002)(235185007)(86362001)(53546011)(66476007)(66946007)(66556008)(66616009)(83380400001)(4326008)(186003)(5660300002)(44832011)(31696002)(36756003)(33964004)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: xNR7gp3zQGAR2TSB3NATBGqnr6ml76gnO6bXG/vjHVknlXQHO+AvnJ5nUyaONqHO1oaTwVNVkI+MTXq0X3tEAOTzICpzhbUn8YBxY7mvlAQtuY9Tzp9aQNuF8uv/8wiTfcgSWvXL7dSeFcBocy0Co1Zd7fUbnnAISXCst/etLZ98pEbx93MpMJExmkN06n2HpXo0KgP4lSMv7rBGy0j5DX7xX53owQqzP4xhfO5nNF+rKKQkfsAfAQTOJQGUZ0vCOGgJhplquA5vrgOZoxXqd0s2AQKGQ/2HA8OjF/uxAAXVER7MCPKfKiF55ZffucqIxWgCZJesQvCJMjVr8c2dceYCKwXIbw5PCb1PDm39DgK0VexGxm/Hu2cERWrN3ykkQNd00elWasg9M7o7yyvEg/5IS//2TkMKQh/BYRqrnCkCT/uC6zh8ZrKelD1uMvgsKlGS+5Zhx08PN7L6Uf2yRi3YYIHnF2J1f8536yLJYR36uBEmv/1PlVV21rqNAuTd7AJTgNJ8cB9CfAhOi3IoxbN+kFc8S5EoNawM4IZwU2WwexWOllGWz4VdqQ4fz2wl2DsZqRXFEjE83KVE3IgKo3XSla848ZIWt9mGrOeMvdSHB2m8NYFDrcCtxPD6gidEMQPjKZzbI/LRMPNNJXAd3xYPKLRZSxZmeTiG60pvB+Dl6uctU6EY44HRXg1UxUG8EE+ZIY4JTiACEaIG+tv05/nohGuq3hXKjmk7lf/4d5rhKNWEFUDLiZcGKpRlqZhMdTWBbyVitqgtkNW6trE9W8B5CrF6ug9NgBI1pF+s2MeoOWrUX9u6RaXRgq7Ri0fydBrBUtJ7CZKxRqnSpEtnX7YqZx3nuuTCk42WPkU+YZZATTuY1cRMZWI1aunArz0qTEpP8Bhfmoo+MJo8SJ8FJ2ljutEWa7Szu4Kse+tw+6E9WuMN1c443qwJhzJGD9CH3sTRyR5u756011T/LAMeiAkU+3wDojPE1J/eVaXDEGnEMRNgyoda1T0OSG8vMWwd8rhEEtVSJrPFHTIx+3dGHAxpFsFixrSlHeCUZrL+jp9XVXmOI1JrWtWiWMBmJHFsMSfVB78mX82fVbR9M6/KaUaXFa2gxyrYSBD+9Gp9njU1q1vRSztp72s2njkc7X0SxblGnwNVZ7wLTb9jCQf2lxRp0W1Z5TFo8robZD0H9u+BrHOxiOu1jotby/1vE42iX2/hLHmvIgyQpvKsWpp/rpvlXIYlN39j5AcbxC5ffuSd0NvvCNaQAEB72BgMPabLMjZ+Zk1iNM/9Z12uzDi597P23PXa2O2n0Pz54N54+ShdBXadNZzMUXb1AQLPx3eb
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: fe447462-dcf2-40fc-8ae9-08d9552a298d
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 01 Aug 2021 20:23:02.4944 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 9U5IX2Um0K0gY/9PV2Ce4ZFXQvYiOCB+60scxgOWw6RcBqoTQxD6r5165cDsJ4TQ
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR02MB6779
Archived-At: <https://mailarchive.ietf.org/arch/msg/111attendees/AuYfiZS7LNl0FImmpc8JMf0eJDo>
Subject: Re: [111attendees] Why do we allow people to edit CodiMD meeting notes who are not logged in?
X-BeenThere: 111attendees@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Mailing list for IETF 111 attendees <111attendees.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/111attendees>, <mailto:111attendees-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/111attendees/>
List-Post: <mailto:111attendees@ietf.org>
List-Help: <mailto:111attendees-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/111attendees>, <mailto:111attendees-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 01 Aug 2021 20:23:15 -0000


On 01/08/2021 16:47, Carsten Bormann wrote:
> OK, so the summary of the 111attendees discussion is that we don’t
> want unauthenticated write access to meeting notes.
Really? Seems to me the risk isn't significant enough to make
someone do work and there's plenty of opportunity to read the
draft meeting notes. I don't really object to requiring note
takers be authenticated but it doesn't seem that worthwhile.

S.