Re: [apps-discuss] webfinger privacy question/suggestion

Evan Prodromou <evan@status.net> Tue, 30 October 2012 18:40 UTC

Return-Path: <evan@status.net>
X-Original-To: apps-discuss@ietfa.amsl.com
Delivered-To: apps-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9EB821F85B3 for <apps-discuss@ietfa.amsl.com>; Tue, 30 Oct 2012 11:40:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=-0.001, BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pRvGyr9fF3KB for <apps-discuss@ietfa.amsl.com>; Tue, 30 Oct 2012 11:40:43 -0700 (PDT)
Received: from office.statusnetinc.com (office.statusnetinc.com [50.57.148.252]) by ietfa.amsl.com (Postfix) with ESMTP id DA27B21F85B1 for <apps-discuss@ietf.org>; Tue, 30 Oct 2012 11:40:42 -0700 (PDT)
Received: from [192.168.0.101] (modemcable065.65-22-96.mc.videotron.ca [96.22.65.65]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by office.statusnetinc.com (Postfix) with ESMTPSA id AECF88D657B for <apps-discuss@ietf.org>; Tue, 30 Oct 2012 18:52:00 +0000 (UTC)
Message-ID: <50901F1C.80706@status.net>
Date: Tue, 30 Oct 2012 14:40:28 -0400
From: Evan Prodromou <evan@status.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:16.0) Gecko/20121028 Thunderbird/16.0.2
MIME-Version: 1.0
To: IETF Apps Discuss <apps-discuss@ietf.org>
References: <508E66FB.4070708@cs.tcd.ie> <0b3b01cdb61c$981dc600$c8595200$@packetizer.com> <508F0870.9050402@cs.tcd.ie> <0b9901cdb636$bf951480$3ebf3d80$@packetizer.com> <508F2B78.2000006@cs.tcd.ie> <0be001cdb64b$eb574560$c205d020$@packetizer.com> <508FA55F.5020608@cs.tcd.ie> <5FC89052-EE84-4C80-BEE8-ABAD7C784F5A@gmx.net> <6.2.5.6.2.20121030093556.0a82b130@resistor.net> <50900F51.5040805@status.net> <CABP7RbdGamtm_fzXaswSf0k+YxDMQFr2qD84DuDzZGCB3FThZA@mail.gmail.com>
In-Reply-To: <CABP7RbdGamtm_fzXaswSf0k+YxDMQFr2qD84DuDzZGCB3FThZA@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------070109080109050605040009"
Subject: Re: [apps-discuss] webfinger privacy question/suggestion
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Oct 2012 18:40:43 -0000

I'd suggest a mechanism like the following:

 1. Always provide some discovery data at the endpoint, even if it's empty.
 2. If some form of authentication is given, show additional items in
    full for the authenticated user.

Dialback authentication would probably work [1], but otherwise we don't 
have a lot of reasonable remote authentication systems.

Local authentication (HTTP Basic, Digest, OAuth, whatever) is also 
reasonable although I think this kind intra-domain discovery more often 
happens with e.g. directory services.

-Evan

[1] http://www.ietf.org/id/draft-prodromou-dialback-00.txt

On 12-10-30 01:54 PM, James M Snell wrote:
>
> Agreed, doing too much in this particular draft would be a mistake. 
> What I want, however, is an incremental strip in the right direction. 
> Right now, hashing the identifier is not an option. It should be. 
> Doing so would allow more complex solutions to be built... solutions 
> that take privacy, confidentiality, authorization and authentication 
> into full account and allow us to span from "only sharing public data" 
> to "sharing any data".
>
> - James
>
> On Oct 30, 2012 10:33 AM, "Evan Prodromou" <evan@status.net 
> <mailto:evan@status.net>> wrote:
>
>     There may be some use to having private sharing of discovery data.
>
>     However, it's such a complicated and difficult problem, that
>     trying to solve it with this version of Webfinger will effectively
>     disallow public discovery.
>
>     That is: it's a terrible morass, which will sink this effort.
>
>     I suggest making a note in the security considerations that
>     Webfinger links are visible to all, so don't put private stuff in
>     there, full stop.
>
>     -Evan
>
>     On 12-10-30 01:18 PM, SM wrote:
>
>         At 03:16 30-10-2012, Hannes Tschofenig wrote:
>
>             Have a look at:
>             http://tools.ietf.org/html/draft-iab-privacy-considerations-04
>
>
>         Hmm, that draft was mentioned several months ago [1].
>
>             I have raised these privacy issues already last year. My
>             comments got ignored.
>
>
>         The following question was asked around 11 months ago [2]:
>
>           "What are you planning to do to ensure the draft properly
>         addresses
>            security, privacy, and netiquette issues?"
>
>         The current plan seems to be: do nothing.
>
>         Regards,
>         -sm
>
>         1.
>         http://www.ietf.org/mail-archive/web/apps-discuss/current/msg04747.html
>         2.
>         http://www.ietf.org/mail-archive/web/apps-discuss/current/msg03804.html
>         _______________________________________________
>         apps-discuss mailing list
>         apps-discuss@ietf.org <mailto:apps-discuss@ietf.org>
>         https://www.ietf.org/mailman/listinfo/apps-discuss
>
>
>
>     -- 
>     Evan Prodromou, CEO and Founder, StatusNet Inc.
>     1124 rue Marie-Anne Est #32, Montreal, Quebec, Canada H2J 2B7
>     E: evan@status.net <mailto:evan@status.net> P: +1-514-554-3826
>
>     _______________________________________________
>     apps-discuss mailing list
>     apps-discuss@ietf.org <mailto:apps-discuss@ietf.org>
>     https://www.ietf.org/mailman/listinfo/apps-discuss
>


-- 
Evan Prodromou, CEO and Founder, StatusNet Inc.
1124 rue Marie-Anne Est #32, Montreal, Quebec, Canada H2J 2B7
E: evan@status.net P: +1-514-554-3826