Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace-usecases-09: (with COMMENT)
Stephen Farrell <stephen.farrell@cs.tcd.ie> Fri, 23 October 2015 08:24 UTC
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AC8CC1B3303 for <ace@ietfa.amsl.com>; Fri, 23 Oct 2015 01:24:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.311
X-Spam-Level:
X-Spam-Status: No, score=-4.311 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rGU07wtwDVCi for <ace@ietfa.amsl.com>; Fri, 23 Oct 2015 01:24:55 -0700 (PDT)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 35D281B32F9 for <ace@ietf.org>; Fri, 23 Oct 2015 01:24:55 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id D926CBE50; Fri, 23 Oct 2015 09:24:52 +0100 (IST)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mULmOPZlvsGG; Fri, 23 Oct 2015 09:24:51 +0100 (IST)
Received: from [10.87.48.91] (unknown [86.46.30.221]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id BA953BE4D; Fri, 23 Oct 2015 09:24:50 +0100 (IST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1445588691; bh=7nyCIwka0d2CnZyCSB4IyUdrzodEWLi+FyFvojqmvyc=; h=Subject:To:References:Cc:From:Date:In-Reply-To:From; b=aOt+ICOypJuNW7wntrxt44t64FFD7o9McaeRcsgbnCSWUCpvS7St1qTgtvjR8ffQU F5qBtojeys5dk76wKhOr1OEtjAkv71+wKmGpFJg8G6DejwZ8BpVElBW4KbQ3T+N9F0 WgnNhgKpHtUDjee4aT9uX2H9nvk02RJaIwohYFaE=
To: Ludwig Seitz <ludwig@sics.se>
References: <20151022132903.23826.2689.idtracker@ietfa.amsl.com> <5629EA01.6020506@sics.se>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <5629EED2.5080005@cs.tcd.ie>
Date: Fri, 23 Oct 2015 09:24:50 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <5629EA01.6020506@sics.se>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/PfnQCqOAH2LOC8PXUxNEcSDgzak>
Cc: ace@ietf.org
Subject: Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace-usecases-09: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 08:24:58 -0000
Hiya, On 23/10/15 09:04, Ludwig Seitz wrote: > On 2015-10-22 15:29, Stephen Farrell wrote: > [...] >> >> 1. Software update is really needed and often missing and >> usually hard. There's at least a need to authenticate and >> authorize new firmware, when there is any update. That may not >> be the same as authorizing a new config. >> >> 2. Alice buys a new device, and would like to know if it is >> calling home or what it is doing before she configures it, or >> perhaps before she accepts it in her network. Even if she >> accepts it, she may want to be able to monitor the data it >> is sending "home" e.g. to ensure her TV is not sending >> data when she inserts a USB stick, if that is undesired. >> >> 3. Device fingerprinting is a threat that ought be considered >> by solution developers, especially if there is no reliable >> software update. Probably the best to be done is to try to >> make it hard for unauthorized parties to fingerprint a device, >> but that's also hard. >> >> 4. Commercial Devices will be end-of-lifed by vendors, and yet >> Alice still needs to be able to use, and perhaos to update, >> the device. That calls for some kind of authorization handover >> which is not quite the same as a change of ownership. >> >> 5. Penetration testing will happen and devices should not barf >> even then. Maybe that's a security consideration worth a >> mention. >> >> See also the secdir review. [1] It'd be good to see a >> response to that. >> >> [1] >> https://www.ietf.org/mail-archive/web/secdir/current/msg06101.html >> > > Hi Stephen, > > Thank you for your comments! > > We are making final adjustments to the document based on the *-DIR and > the ballot comments. > > In the light of the discussion of your comments, Steffi and I are > leaning towards not including them in this draft, since they are of a > more general nature and would fit better in a general IoT/CoRE security > document. > > Would that be ok with you? That is ok, but I disagree of course:-) I do think there are ace-specific use-cases arising from the above. But I can fully understand not wanting to take on such additions at this stage as well. S > > > /Ludwig > > >
- [Ace] Stephen Farrell's Yes on draft-ietf-ace-use… Stephen Farrell
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Carsten Bormann
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Stephen Farrell
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Kumar, Sandeep
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Carsten Bormann
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Kathleen Moriarty
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Ludwig Seitz
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Stephen Farrell
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Kathleen Moriarty
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Ludwig Seitz
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Stefanie Gerdes
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Kathleen Moriarty
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Ludwig Seitz
- Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace… Kathleen Moriarty