Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders

Phillip Hallam-Baker <phill@hallambaker.com> Thu, 22 June 2023 15:56 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 09CB7C15153E for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 08:56:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.549
X-Spam-Level:
X-Spam-Status: No, score=-1.549 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.096, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5ICYEtgm-iH2 for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 08:56:53 -0700 (PDT)
Received: from mail-oo1-f52.google.com (mail-oo1-f52.google.com [209.85.161.52]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08573C1519B0 for <gendispatch@ietf.org>; Thu, 22 Jun 2023 08:56:51 -0700 (PDT)
Received: by mail-oo1-f52.google.com with SMTP id 006d021491bc7-55e4d71a5daso3482735eaf.0 for <gendispatch@ietf.org>; Thu, 22 Jun 2023 08:56:51 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1687449411; x=1690041411; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=SW0ZtCFvL8Hb+9a2tBxJkZ+oQEWvEXyWj9D1b2MUN58=; b=LxhFNkOyKs1mGKSqYs9F3oYF06t86htYT6792XTgDfts9VvEFxk+KqktzoGzLaRs4E YabOLF6hcVy1BRmMIgTaOQywz4Gb+Ez5qESfJkXoNtNQ1gmVy331wtJDevbhWPnzGJVY 7n4YkjEhPFQxzVfAF/Ij5pnWNqzLKj4c5wqk+gI/pR2KbkuuOnNdAnRpo+YcTh1KZELv 6F2SUA+ZchMk+pKjv/wSfTapFiqSOX2x3vZyv2UovEkRM93rHv60gqdVXHGTLQtcn5My nLa6t2loIh0OYXo9WDgsyAL2fjzS7YOpgk5yV7NIji8+zPQYfP9H4mlBPoKdv6JkJOUS DqhA==
X-Gm-Message-State: AC+VfDz3Y3ZYWof3W/3Dbb2Elxl93YwKKsQNlLSerfx7b5dijVmpdxMZ sW+qmeYgxcDpK0xF33o6GJsndZlt16EO5oGbTqE=
X-Google-Smtp-Source: ACHHUZ5PLVbmh6KPEzneKRFHc+mRk6M+ixrhxtpatnn1ttgLm6vYHZp/ORwDTN/qBDPsk/W1e5GA6Pu/vxgH5gapN00=
X-Received: by 2002:a4a:d451:0:b0:558:b424:8c31 with SMTP id p17-20020a4ad451000000b00558b4248c31mr7428722oos.0.1687449411097; Thu, 22 Jun 2023 08:56:51 -0700 (PDT)
MIME-Version: 1.0
References: <6b349547-a26b-4028-14a7-6be3f3e44321@huitema.net> <20230620163302.ACBA8F6FA18F@ary.qy> <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com> <AA947AC2-D22E-417A-BDF0-96E9F473FF55@gmail.com>
In-Reply-To: <AA947AC2-D22E-417A-BDF0-96E9F473FF55@gmail.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Thu, 22 Jun 2023 11:56:39 -0400
Message-ID: <CAMm+LwiihT9XmX4e79_QV+5+6U8EJrrf16DH1A0AcQO19DcyKg@mail.gmail.com>
To: Bob Hinden <bob.hinden@gmail.com>
Cc: Vittorio Bertola <vittorio.bertola=40open-xchange.com@dmarc.ietf.org>, John Levine <johnl@taugh.com>, gendispatch@ietf.org
Content-Type: multipart/alternative; boundary="000000000000b99b0305feb9eecc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/1O48DX9nVa0Qiwh2claWVbCJ0FY>
Subject: Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Jun 2023 15:56:58 -0000

People keep raising end to end encryption as an issue here and so I would
just like to make a clarification.

But first, I will note that before the pandemic, MIT and Harvard were
running annual seminars discussing emerging cyber-norms which provided one
forum in which technologists and policy makers could discuss these issues
under Chatham House rules. Perhaps we should get back to that.


Of course the question of whether applications have backdoors is a policy
question. There is absolutely no need for a policy maker to understand the
technology in order to have an informed opinion on the technology. Since a
member of my family survived two assassination attempts by the PIRA
(Brighton Bomb, Downing St mortar), I have always been very aware of the
threat of terrorism in my technical work. But I am also aware of rather a
lot more, probably more aware than most people with 'UK Cabinet Office' on
their IETF badges.

All they need to do is to explain is which governments they want to have
access to the backdoor. I am a UK citizen so if I put any backdoors in, the
UK would be first in line. Is the US OK with that? Well I guess it might
but what about France? What do we do when it comes to countries that are
allies but not members of NATO? What about Israel? What about Saud?

What international institutions are going to be established to govern these
lawful intercept capabilities? Interpol? The ECJ?

Oh and all my code is open source and available on GitHub so if I did
insert a backdoor how do I prevent someone forking my code and removing it?

None of these are technical questions, they are all policy questions.


Of course, an understanding of the technology is essential to writing
legislation. Take the drafting of the OSA which requires 'service
providers' to provide access to communications. The assumption being that
the only business model for messaging is one in which the network effect
drives everything into a monopoly or cartel with a tiny number of providers
that can be controlled by government. The legislation does not anticipate a
UK citizen being able to choose a US service provider or being their own
service provider.

I have to wonder if anyone in HMG has considered the fact that email and
messaging services are not profit centers in their own right for the major
technology providers and that the likely response to the OSA will be to
shutter services in the UK and/or reduce functionality. I cannot see a
corporation with a trillion dollar market cap risking their global brand by
complying with OSA for the sake of a service that isn't a profit center. So
has anyone in HMG considered the possibility that Google shuts down Gmail
for the UK or the effect that might have on the economy? It is rather
easier for Signal to comply, all they need to do is block image attachments
for UK communications. But SMTP without MIME attachments would grind
commerce to a halt in most countries.


I do have a very good idea of the horrors that will be unleashed by
providing an entirely end-to-end secure communication infrastructure that
encompases data at rest as well as data in transit. A Mesh social media
discussion forum is end-to-end encrypted and only visible to the
participants, the service provider has no access to the plaintext.

But I can also see the effect of having hostile intelligence forces
performing Hack-Select-and-Leak attacks as described at length in the
Mueller report.

It is clear we should be discussing these issues. It is also clear that
this is not the place.