Re: [Endymail] Another view of the problem and what the IETF could do

Michael Kjörling <michael@kjorling.se> Thu, 04 September 2014 13:19 UTC

Return-Path: <michael@kjorling.se>
X-Original-To: endymail@ietfa.amsl.com
Delivered-To: endymail@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CA4C1A889F for <endymail@ietfa.amsl.com>; Thu, 4 Sep 2014 06:19:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.519
X-Spam-Level:
X-Spam-Status: No, score=-0.519 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, HELO_EQ_SE=0.35, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.668, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VAVxCVj9hzcO for <endymail@ietfa.amsl.com>; Thu, 4 Sep 2014 06:19:10 -0700 (PDT)
Received: from nekare.kjorling.se (nekare.kjorling.se [89.221.249.175]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1576A1A8891 for <endymail@ietf.org>; Thu, 4 Sep 2014 06:19:08 -0700 (PDT)
Received: by nekare.kjorling.se (Postfix, from userid 1001) id 2D07E114075; Thu, 4 Sep 2014 13:19:06 +0000 (UTC)
X-Spam-Details: BAYES_00=-1.9, SPF_FAIL=0.001 (nekare.kjorling.se)
Received: from yeono.kjorling.se (h-9-65.a328.priv.bahnhof.se [46.59.9.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "yeono", Issuer "yeono" (not verified)) by nekare.kjorling.se (Postfix) with ESMTPS id 0A37D114073 for <endymail@ietf.org>; Thu, 4 Sep 2014 13:18:58 +0000 (UTC)
Received: from yeono.kjorling.se (localhost [127.0.0.1]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (Client did not present a certificate) by yeono (Postfix) with ESMTPS id 88E7E140031 for <endymail@ietf.org>; Thu, 4 Sep 2014 15:18:57 +0200 (CEST)
Date: Thu, 4 Sep 2014 13:18:56 +0000
From: Michael =?utf-8?B?S2rDtnJsaW5n?= <michael@kjorling.se>
To: endymail@ietf.org
Message-ID: <20140904131856.GM603@yeono.kjorling.se>
References: <CAHBU6iuxfqs9RszSaJLaTV_obKBCJ9Pzii+t9XANN3q+bJm-3Q@mail.gmail.com> <5404A3A3.9050506@cisco.com> <A8423D66-369A-4511-8A4C-EE4545E49111@adamcaudill.com> <3093EBC2-B370-4675-B53D-20162E3D0CC9@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <3093EBC2-B370-4675-B53D-20162E3D0CC9@gmail.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/endymail/qIjDw--NOtG0JFbqHJHvbHKVPeM
Subject: Re: [Endymail] Another view of the problem and what the IETF could do
X-BeenThere: endymail@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <endymail.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/endymail>, <mailto:endymail-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/endymail/>
List-Post: <mailto:endymail@ietf.org>
List-Help: <mailto:endymail-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/endymail>, <mailto:endymail-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2014 13:19:12 -0000

On 2 Sep 2014 16:36 -0400, from hallam@gmail.com (Phillip Hallam-Baker):
> Since spam is a concern, we might well not want to answer question
> 1, or at least not to just anyone.

This is one of the points I raised in [1], and which frankly I felt
went unaddressed.


> For in person trust anchor exchange, QR codes are the way to go.

Only if you're willing to basically limit "whatever we end up
discussing" to people who have the ability to process a random
encountered QR code in the field. While smartphones and ubiquitous
networking is common in many Western countries, designing a protocol
around only that seems rather excluding. Just to mention one example,
I myself would have no way to process that QR code, and found myself
in a discussion on a non-technical mailing list the other day where
several people commented about either not having cell phones at all,
or having only old "dumb phone" style phones.

Do we want to exclude those people from establishing that trust
anchor?


[1] Fri, 29 Aug 2014 09:11:33 +0000 http://mailarchive.ietf.org/arch/msg/endymail/mSmLHfs0kzZNE9LaYdBDjHtN8ok

-- 
Michael Kjörling • https://michael.kjorling.semichael@kjorling.se
OpenPGP B501AC6429EF4514 https://michael.kjorling.se/public-keys/pgp
                 “People who think they know everything really annoy
                 those of us who know we don’t.” (Bjarne Stroustrup)