Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders

Phillip Hallam-Baker <phill@hallambaker.com> Thu, 22 June 2023 18:06 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81848C1519A8 for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 11:06:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.549
X-Spam-Level:
X-Spam-Status: No, score=-1.549 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.096, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q2KnE1aYSHBD for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
Received: from mail-oo1-f53.google.com (mail-oo1-f53.google.com [209.85.161.53]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91588C15108E for <gendispatch@ietf.org>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
Received: by mail-oo1-f53.google.com with SMTP id 006d021491bc7-55e04a83465so4858615eaf.3 for <gendispatch@ietf.org>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1687457195; x=1690049195; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=tXjk+XaTpDB9iBVOop/cDtRQ/nrw3QIGby3RR898xEA=; b=Ue7jlnKZFbdDF9INlLv4BksZhhhOjLNd68jE03VgmSdxIKaexZyM/Mem181k3gHF0c QdFwCejIgaAZxq/3nIqjOea+HNv2kLBxO2n5v98Mwzim+NHCTSpZYjlmc7qcXAxq3VOr rIkISDsEFwxrpdz7IAedD3x1q7N/3eC6mfvDhRyS3rYKcm+Igjj4mlAs3egFh1NV3u89 TqR2AzaIEoLAQd6kZ0ckjiIBff4Q5HbybtE3K891n5OC8QKTD8VdZij7Z7D5OuynVvSM sf6Dgae120SeYJVoc18Sh4ciPGr17omivgkUk+nnNr9GJbNB24rOmLZTFeL+u3p3233b RYGA==
X-Gm-Message-State: AC+VfDxM9UbsAuYJYh/ENBh+oVObZUsItzxkti88XS0fpcGkOqIVuFmg eL2Ja5vf+5OTYlx7k77MtBkBojsPGcOWBqCMLTiVgVRrVYQ=
X-Google-Smtp-Source: ACHHUZ5svwfeiMevbBlDodL9XwEgZFKpH97CU8FtISmMs9eairPJtzPHae4NQGUE6Z7lA9jffjiNx0RV9/zgVVsVcLU=
X-Received: by 2002:a4a:ddcc:0:b0:560:aa1d:fe01 with SMTP id i12-20020a4addcc000000b00560aa1dfe01mr4844728oov.2.1687457194616; Thu, 22 Jun 2023 11:06:34 -0700 (PDT)
MIME-Version: 1.0
References: <6b349547-a26b-4028-14a7-6be3f3e44321@huitema.net> <20230620163302.ACBA8F6FA18F@ary.qy> <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com> <59b7283c-1ea7-82ea-35da-28b659a27fb5@taugh.com>
In-Reply-To: <59b7283c-1ea7-82ea-35da-28b659a27fb5@taugh.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Thu, 22 Jun 2023 14:06:23 -0400
Message-ID: <CAMm+LwjBAMT-GGzA-kA7SDwJpd5DAtnUW7g+MEomHTvOf=JXAA@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Cc: Vittorio Bertola <vittorio.bertola@open-xchange.com>, gendispatch@ietf.org
Content-Type: multipart/alternative; boundary="000000000000a8ad2e05febbbe12"
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/JSmDn_NPK6bYRi_QE80gyxGU4xk>
Subject: Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Jun 2023 18:06:36 -0000

On Thu, Jun 22, 2023 at 12:23 PM John R Levine <johnl@taugh.com> wrote:

> On Thu, 22 Jun 2023, Vittorio Bertola wrote:
> >> clear understanding of the technology. That's how you end up with
> >> cryptographers repeatedly explaining why we can't put back doors in
> >> cryptosystems and policy people telling us we have to, just nerd
> >> harder.
> >
> > Don't misunderstand me, I do think that backdoors in crypto are a bad
> > idea, but: is the cryptographers' explanation of why we can't have them
> > a technical or a policy argument? I always understood it as "if we do,
> > there is no way to eliminate the risk that they will fall into the wrong
> > hands", but whether that risk is acceptable or not and under which
> > conditions is a policy decision, not a technical one.
>
> I think it's more a persistent misunderstanding of what the risks are.
>
> Law enforcement has a century of experience with wiretaps.  They have a
> gradual failure model.  If I lie to a judge or bribe a phone tech, I can
> get taps on a few phone lines but I can't listen in to the entire phone
> system.  As we all know, software isn't like that, often fails
> catastrophically, and we have no way to ensure any particular piece of
> software doesn't have catastrophic bugs.  Putting the software in hardware
> doesn't help.  The 1990s Clipper chip which was supposed to provide a
> controlled key escrow designed by the NSA turned out to have bugs that
> made it easy to evode the escrow.
>

The catastrophic failure mode is very relevant here. One of the (many)
reasons
I think crypto currencies are a terrible idea is precisely because the
wallets are
vulnerable to endpoint attacks.

In the case of Lawful Intercept, the failure mode is 'insider threat' as
demonstrated by Ed Snowden. The head of the counterintelligence desk
of the NY FBI office is currently charged with illegally accepting money
from
a Russian oligarch.


Phill recently sent a message listing the impossible set of questions
> you'd have to answer to build a backdoored system.  But if you believe
> that the wiretap model is the way things work, you don't have to answer
> any of those questions.  You just have to tell the nerds to nerd harder
> and build something that fails like wiretaps do.
>

I think it is rather worse than that. Several of the people I knew at
Oxford
were in government. One of the few whose opinion I respect, Ed Lazarus
was booted out of his party and kicked upstairs for telling the truth about
a government policy.

The real problem is that a certain section of the political class is
uninterested
in the business of actually governing. They are utterly uninterested in
policy
arguments of any type, their one and only interest is gaining coverage in
the media. For the past decade, public discourse in my country
has been dominated by a small cabal of Eton and Oxford educated
individuals railing against 'the elites'.


> So far we have largely failed to get policy people to understand the way
> software fails or how to evaluate its risks.  To some extent that's
> because they don't want to, but there's not much we can do about that.
>

The way to gain the attention of UK politicians is the phrase 'dangerous
dogs bill'.

But rather than just railing against the politicians, it is also important
to
note that the tech industry itself has made establishing a discourse
difficult.
Cyber-engagement is an area with direct impact on national security and
so it is hardly surprising that it is the subject of intense government
scrutiny.
Supply chain compromises are no longer a theoretical possibility, they are
an observed fact. And worse, absolutely nobody knows who is really doing
any of it except for the stuff they are doing themselves.

Government does actually have a legitimate interest in ensuring that
communications do not become a de-facto monopoly. Government has a
legitimate interest in protecting personal privacy as well.

It is not hard to see why policy makers would believe that we are fibbing
about the technical impossibility of backdoors when so many companies
are fibbing about the possibility of interoperable messaging.

We are not in the 1990s any more. 'Move fast and break things' is not
an acceptable approach after your technology has become a critical
infrastructure.