Re: [Gen-art] Gen-ART Last Call review of draft-ietf-dprive-rfc7626-bis-03

Sara Dickinson <sara@sinodun.com> Wed, 18 December 2019 13:47 UTC

Return-Path: <sara@sinodun.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 07D6012004C; Wed, 18 Dec 2019 05:47:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level:
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sinodun.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wapj7h2VSJVp; Wed, 18 Dec 2019 05:47:29 -0800 (PST)
Received: from balrog.mythic-beasts.com (balrog.mythic-beasts.com [IPv6:2a00:1098:0:82:1000:0:2:1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2EC9712003E; Wed, 18 Dec 2019 05:47:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sinodun.com ; s=mythic-beasts-k1; h=To:Date:Subject:From; bh=jDvHMQxQpcHzuuCVS2hZnr1WdOBencdPNlShX2AXtiI=; b=gd4YtFweQ4jfTK95BTmys+iZn8 GeZg0wYKQBd75VID6s9bbnOgZ17wRpDreGyac2q5xvPQMKC1LHQbYicrSnd8xA1GB44eB8RLlytGk Zq7sRiVZyZP0gxdr5uTc/0aHmN+ql1c0zchOIzu4ptA/0DmbZ3XsOgy93STrVoQBBd4MY3XdminST Qw8LYzL7OvICvuHH7uhQKiH6mCbI1MtHNKPlrv6zHkiyCyMiGADSfdQ3RJcoqBNQBzS0p+TmMx54d jhbSienenzbmTEB8CKarxHBOAHWbMCQrNQVaAZie4l/VrTJbG2zF6fTdbKkzudnq1Ob3O8hY5hlzG 0xpzRSgw==;
Received: from [2001:b98:204:102:fffa::2] (port=51557) by balrog.mythic-beasts.com with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92.3) (envelope-from <sara@sinodun.com>) id 1ihZff-0006Wx-IG; Wed, 18 Dec 2019 13:47:27 +0000
From: Sara Dickinson <sara@sinodun.com>
Message-Id: <D5C4DB2B-842D-4A1E-B2D2-AEDF3056895E@sinodun.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_CB4FB23F-A623-434A-B1AE-FCAEC4874395"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Wed, 18 Dec 2019 13:47:21 +0000
In-Reply-To: <8D38A6CC-C42C-4B5B-8FE2-F12F4178F1DF@ericsson.com>
Cc: "draft-ietf-dprive-rfc7626-bis.all@ietf.org" <draft-ietf-dprive-rfc7626-bis.all@ietf.org>, "gen-art@ietf.org" <gen-art@ietf.org>
To: Meral Shirazipour <meral.shirazipour@ericsson.com>
References: <8D38A6CC-C42C-4B5B-8FE2-F12F4178F1DF@ericsson.com>
X-Mailer: Apple Mail (2.3445.104.11)
X-BlackCat-Spam-Score: 4
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/67iMAiKHF_zwKYA3scHH8NDCkZM>
Subject: Re: [Gen-art] Gen-ART Last Call review of draft-ietf-dprive-rfc7626-bis-03
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Dec 2019 13:47:31 -0000


> On 3 Dec 2019, at 06:52, Meral Shirazipour <meral.shirazipour@ericsson.com> wrote:
> 
> I am the assigned Gen-ART reviewer for this draft. The General Area Review Team (Gen-ART) reviews all IETF documents being processed by the IESG for the IETF Chair.  Please treat these comments just like any other last call comments.
>  
> For more information, please see the FAQ at <https://trac.ietf.org/trac/gen/wiki/GenArtfaq <https://trac.ietf.org/trac/gen/wiki/GenArtfaq>>.
>  
> Document: draft-ietf-dprive-rfc7626-bis-03
>  
> Reviewer: Meral Shirazipour
> Review Date: 2019-12-02
> IETF LC End Date: 2019-12-02
> IESG Telechat date: NA
>  
>  
> Summary: This draft is ready to be published as Informational RFC with some issues (I would recommend taking into consideration the comments received on the mailing list)

Hi Meral, 

Thanks for the review!

>  
> Major issues:
>  
> Minor issues:
>  
> Nits/editorial comments:
> It would have been interesting to have this draft also mention the additional/potential risks for non-web applications. IoT was briefly mentioned in Section 3.6. What about other applications? Is there any other privacy risks beyond just identifying the content being requested?
>  

It is a good point but nothing really springs to mind in terms of additional concrete privacy risks I’ve seen documented that have been identified for non-web applications. There have been various reports of malware using DoH but they tend to identify attacks that are equally possible with other forms of encryption…..

Sara.