Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
Phillip Hallam-Baker <phill@hallambaker.com> Thu, 22 June 2023 18:06 UTC
Return-Path: <hallam@gmail.com>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81848C1519A8 for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 11:06:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.549
X-Spam-Level:
X-Spam-Status: No, score=-1.549 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.096, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q2KnE1aYSHBD for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
Received: from mail-oo1-f53.google.com (mail-oo1-f53.google.com [209.85.161.53]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91588C15108E for <gendispatch@ietf.org>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
Received: by mail-oo1-f53.google.com with SMTP id 006d021491bc7-55e04a83465so4858615eaf.3 for <gendispatch@ietf.org>; Thu, 22 Jun 2023 11:06:35 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1687457195; x=1690049195; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=tXjk+XaTpDB9iBVOop/cDtRQ/nrw3QIGby3RR898xEA=; b=Ue7jlnKZFbdDF9INlLv4BksZhhhOjLNd68jE03VgmSdxIKaexZyM/Mem181k3gHF0c QdFwCejIgaAZxq/3nIqjOea+HNv2kLBxO2n5v98Mwzim+NHCTSpZYjlmc7qcXAxq3VOr rIkISDsEFwxrpdz7IAedD3x1q7N/3eC6mfvDhRyS3rYKcm+Igjj4mlAs3egFh1NV3u89 TqR2AzaIEoLAQd6kZ0ckjiIBff4Q5HbybtE3K891n5OC8QKTD8VdZij7Z7D5OuynVvSM sf6Dgae120SeYJVoc18Sh4ciPGr17omivgkUk+nnNr9GJbNB24rOmLZTFeL+u3p3233b RYGA==
X-Gm-Message-State: AC+VfDxM9UbsAuYJYh/ENBh+oVObZUsItzxkti88XS0fpcGkOqIVuFmg eL2Ja5vf+5OTYlx7k77MtBkBojsPGcOWBqCMLTiVgVRrVYQ=
X-Google-Smtp-Source: ACHHUZ5svwfeiMevbBlDodL9XwEgZFKpH97CU8FtISmMs9eairPJtzPHae4NQGUE6Z7lA9jffjiNx0RV9/zgVVsVcLU=
X-Received: by 2002:a4a:ddcc:0:b0:560:aa1d:fe01 with SMTP id i12-20020a4addcc000000b00560aa1dfe01mr4844728oov.2.1687457194616; Thu, 22 Jun 2023 11:06:34 -0700 (PDT)
MIME-Version: 1.0
References: <6b349547-a26b-4028-14a7-6be3f3e44321@huitema.net> <20230620163302.ACBA8F6FA18F@ary.qy> <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com> <59b7283c-1ea7-82ea-35da-28b659a27fb5@taugh.com>
In-Reply-To: <59b7283c-1ea7-82ea-35da-28b659a27fb5@taugh.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Thu, 22 Jun 2023 14:06:23 -0400
Message-ID: <CAMm+LwjBAMT-GGzA-kA7SDwJpd5DAtnUW7g+MEomHTvOf=JXAA@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Cc: Vittorio Bertola <vittorio.bertola@open-xchange.com>, gendispatch@ietf.org
Content-Type: multipart/alternative; boundary="000000000000a8ad2e05febbbe12"
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/JSmDn_NPK6bYRi_QE80gyxGU4xk>
Subject: Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Jun 2023 18:06:36 -0000
On Thu, Jun 22, 2023 at 12:23 PM John R Levine <johnl@taugh.com> wrote: > On Thu, 22 Jun 2023, Vittorio Bertola wrote: > >> clear understanding of the technology. That's how you end up with > >> cryptographers repeatedly explaining why we can't put back doors in > >> cryptosystems and policy people telling us we have to, just nerd > >> harder. > > > > Don't misunderstand me, I do think that backdoors in crypto are a bad > > idea, but: is the cryptographers' explanation of why we can't have them > > a technical or a policy argument? I always understood it as "if we do, > > there is no way to eliminate the risk that they will fall into the wrong > > hands", but whether that risk is acceptable or not and under which > > conditions is a policy decision, not a technical one. > > I think it's more a persistent misunderstanding of what the risks are. > > Law enforcement has a century of experience with wiretaps. They have a > gradual failure model. If I lie to a judge or bribe a phone tech, I can > get taps on a few phone lines but I can't listen in to the entire phone > system. As we all know, software isn't like that, often fails > catastrophically, and we have no way to ensure any particular piece of > software doesn't have catastrophic bugs. Putting the software in hardware > doesn't help. The 1990s Clipper chip which was supposed to provide a > controlled key escrow designed by the NSA turned out to have bugs that > made it easy to evode the escrow. > The catastrophic failure mode is very relevant here. One of the (many) reasons I think crypto currencies are a terrible idea is precisely because the wallets are vulnerable to endpoint attacks. In the case of Lawful Intercept, the failure mode is 'insider threat' as demonstrated by Ed Snowden. The head of the counterintelligence desk of the NY FBI office is currently charged with illegally accepting money from a Russian oligarch. Phill recently sent a message listing the impossible set of questions > you'd have to answer to build a backdoored system. But if you believe > that the wiretap model is the way things work, you don't have to answer > any of those questions. You just have to tell the nerds to nerd harder > and build something that fails like wiretaps do. > I think it is rather worse than that. Several of the people I knew at Oxford were in government. One of the few whose opinion I respect, Ed Lazarus was booted out of his party and kicked upstairs for telling the truth about a government policy. The real problem is that a certain section of the political class is uninterested in the business of actually governing. They are utterly uninterested in policy arguments of any type, their one and only interest is gaining coverage in the media. For the past decade, public discourse in my country has been dominated by a small cabal of Eton and Oxford educated individuals railing against 'the elites'. > So far we have largely failed to get policy people to understand the way > software fails or how to evaluate its risks. To some extent that's > because they don't want to, but there's not much we can do about that. > The way to gain the attention of UK politicians is the phrase 'dangerous dogs bill'. But rather than just railing against the politicians, it is also important to note that the tech industry itself has made establishing a discourse difficult. Cyber-engagement is an area with direct impact on national security and so it is hardly surprising that it is the subject of intense government scrutiny. Supply chain compromises are no longer a theoretical possibility, they are an observed fact. And worse, absolutely nobody knows who is really doing any of it except for the stuff they are doing themselves. Government does actually have a legitimate interest in ensuring that communications do not become a de-facto monopoly. Government has a legitimate interest in protecting personal privacy as well. It is not hard to see why policy makers would believe that we are fibbing about the technical impossibility of backdoors when so many companies are fibbing about the possibility of interoperable messaging. We are not in the 1990s any more. 'Move fast and break things' is not an acceptable approach after your technology has become a critical infrastructure.
- [Gendispatch] Updated draft: Policy experts are I… Stacie Hoffmann
- Re: [Gendispatch] Updated draft: Policy experts a… Stephen Farrell
- Re: [Gendispatch] Updated draft: Policy experts a… Joel Halpern
- Re: [Gendispatch] Updated draft: Policy experts a… Stephen Farrell
- Re: [Gendispatch] Updated draft: Policy experts a… Brian E Carpenter
- Re: [Gendispatch] Updated draft: Policy experts a… Christian Huitema
- Re: [Gendispatch] Updated draft: Policy experts a… Stacie Hoffmann
- Re: [Gendispatch] Updated draft: Policy experts a… Stephen Farrell
- Re: [Gendispatch] Updated draft: Policy experts a… John Levine
- Re: [Gendispatch] Updated draft: Policy experts a… Vittorio Bertola
- Re: [Gendispatch] Updated draft: Policy experts a… Stephen Farrell
- Re: [Gendispatch] Updated draft: Policy experts a… Livingood, Jason
- Re: [Gendispatch] Updated draft: Policy experts a… Bob Hinden
- Re: [Gendispatch] Updated draft: Policy experts a… Adrian Farrel
- Re: [Gendispatch] Updated draft: Policy experts a… Phillip Hallam-Baker
- Re: [Gendispatch] Updated draft: Policy experts a… John R Levine
- Re: [Gendispatch] Updated draft: Policy experts a… Phillip Hallam-Baker
- Re: [Gendispatch] Updated draft: Policy experts a… Martin Thomson
- Re: [Gendispatch] Updated draft: Policy experts a… Eric Rescorla
- Re: [Gendispatch] Updated draft: Policy experts a… Eric Rescorla
- Re: [Gendispatch] Updated draft: Policy experts a… Eliot Lear
- Re: [Gendispatch] Updated draft: Policy experts a… Christian Huitema
- Re: [Gendispatch] Updated draft: Policy experts a… Eliot Lear
- Re: [Gendispatch] Updated draft: Policy experts a… Colin Perkins
- Re: [Gendispatch] Updated draft: Policy experts a… Vittorio Bertola
- Re: [Gendispatch] Updated draft: Policy experts a… Jay Daley
- Re: [Gendispatch] Updated draft: Policy experts a… Eric Rescorla
- [Gendispatch] savage beasts at IETF meetings Jim Reid
- Re: [Gendispatch] Updated draft: Policy experts a… Mallory Knodel
- Re: [Gendispatch] Updated draft: Policy experts a… Phillip Hallam-Baker
- Re: [Gendispatch] Updated draft: Policy experts a… Brian E Carpenter
- Re: [Gendispatch] Updated draft: Policy experts a… John Levine
- Re: [Gendispatch] Updated draft: Policy experts a… Stacie Hoffmann
- Re: [Gendispatch] Updated draft: Policy experts a… Vittorio Bertola
- Re: [Gendispatch] Updated draft: Policy experts a… John Levine
- Re: [Gendispatch] Updated draft: Policy experts a… Rob Sayre
- Re: [Gendispatch] Updated draft: Policy experts a… Andrew Alston
- Re: [Gendispatch] Updated draft: Policy experts a… Andrew Alston
- Re: [Gendispatch] Updated draft: Policy experts a… Tony Rutkowski
- Re: [Gendispatch] Updated draft: Policy experts a… Salz, Rich
- Re: [Gendispatch] Updated draft: Policy experts a… Andrew Alston
- [Gendispatch] Diversity and the IETF Andrew Campling
- Re: [Gendispatch] Updated draft: Policy experts a… Vittorio Bertola
- Re: [Gendispatch] Updated draft: Policy experts a… Rob Sayre
- Re: [Gendispatch] Updated draft: Policy experts a… Tony Rutkowski
- Re: [Gendispatch] Updated draft: Policy experts a… Rob Sayre
- Re: [Gendispatch] Updated draft: Policy experts a… Phillip Hallam-Baker
- Re: [Gendispatch] Updated draft: Policy experts a… Mallory Knodel
- Re: [Gendispatch] Diversity and the IETF Brian E Carpenter
- Re: [Gendispatch] Updated draft: Policy experts a… Eliot Lear
- Re: [Gendispatch] Updated draft: Policy experts a… Stacie Hoffmann