Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders

Adrian Farrel <adrian@olddog.co.uk> Thu, 22 June 2023 15:36 UTC

Return-Path: <adrian@olddog.co.uk>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0155C137393 for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 08:36:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=olddog.co.uk
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 28AE2xe9wvOI for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 08:36:07 -0700 (PDT)
Received: from mta8.iomartmail.com (mta8.iomartmail.com [62.128.193.158]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0FA3FC14CF1F for <gendispatch@ietf.org>; Thu, 22 Jun 2023 08:36:06 -0700 (PDT)
Received: from vs2.iomartmail.com (vs2.iomartmail.com [10.12.10.123]) by mta8.iomartmail.com (8.14.7/8.14.7) with ESMTP id 35MFa1Nn006554; Thu, 22 Jun 2023 16:36:01 +0100
Received: from vs2.iomartmail.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4FA7D46050; Thu, 22 Jun 2023 16:36:01 +0100 (BST)
Received: from vs2.iomartmail.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 42C734604C; Thu, 22 Jun 2023 16:36:01 +0100 (BST)
Received: from asmtp3.iomartmail.com (unknown [10.12.10.224]) by vs2.iomartmail.com (Postfix) with ESMTPS; Thu, 22 Jun 2023 16:36:01 +0100 (BST)
Received: from LAPTOPK7AS653V (82-69-109-75.dsl.in-addr.zen.co.uk [82.69.109.75]) (authenticated bits=0) by asmtp3.iomartmail.com (8.14.7/8.14.7) with ESMTP id 35MFa07h030818 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Thu, 22 Jun 2023 16:36:00 +0100
Reply-To: adrian@olddog.co.uk
From: Adrian Farrel <adrian@olddog.co.uk>
To: 'Bob Hinden' <bob.hinden@gmail.com>, 'Vittorio Bertola' <vittorio.bertola=40open-xchange.com@dmarc.ietf.org>
Cc: 'John Levine' <johnl@taugh.com>, gendispatch@ietf.org
References: <6b349547-a26b-4028-14a7-6be3f3e44321@huitema.net> <20230620163302.ACBA8F6FA18F@ary.qy> <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com> <AA947AC2-D22E-417A-BDF0-96E9F473FF55@gmail.com>
In-Reply-To: <AA947AC2-D22E-417A-BDF0-96E9F473FF55@gmail.com>
Date: Thu, 22 Jun 2023 16:35:59 +0100
Organization: Old Dog Consulting
Message-ID: <046101d9a51f$3ef0fbd0$bcd2f370$@olddog.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Content-Language: en-gb
Thread-Index: AQJVz5zE/KyNM7xe2Us6Dtwd+UT7YQD+YEZ1AlKa4AECOoD5jK5yQMQQ
X-Originating-IP: 82.69.109.75
X-Thinkmail-Auth: adrian@olddog.co.uk
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=olddog.co.uk; h=reply-to :from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:content-type:content-transfer-encoding; s= 20221128; bh=SVnkUK5mTTPUqqD5qGJY1ZYQTza+xrp3hq3UHRFNSms=; b=kMY WBog1gn6DhPOTFwfw91ALOWkwxvRJiyEiji6njclHfwl14plcYvWmexFURxqnnJ7 04BxZ39cIpyt2YYjvkTveCxFR6VjrhdE1Ths9m2vTzWf/BpCErP60XRQluRenLLe VEo3QzIlCkfxrCFDptXNl12/k3G9ZzrwSUEt6N10C4WBbckg8/mdh6Vov18TuOaH UmpiWo9WhsextXaawfPFnw7mh2eR7TzRdMZBEXrtbc8QmN5y5q2PeHyJvWJXmaT7 Ny76XvxfIm1udRM9pZlAZRxMQCjX3Mk4NjKEQJpm9numkZcM/Br1CjuXFttJaCl/ I7vLrlsa/l2mFFv+AHg==
X-TM-AS-GCONF: 00
X-TM-AS-Product-Ver: IMSVA-9.1.0.2090-9.0.0.1002-27708.000
X-TM-AS-Result: No--5.947-10.0-31-10
X-imss-scan-details: No--5.947-10.0-31-10
X-TMASE-Version: IMSVA-9.1.0.2090-9.0.1002-27708.000
X-TMASE-Result: 10--5.947100-10.000000
X-TMASE-MatchedRID: QW5G6BKkLTrxIbpQ8BhdbPHkpkyUphL9Q/2UjISFQXAgxiy2xJZXvf+Y Kp2Mb6xJ1/cbUGFdXl714kzA6p5wPLUR0gbk4nO13nHtGkYl/VoBqNb4Qv6VoxG3US/I5cDRRtU L4XifTnulTxLMJ4JCL+WAL3Qlk9WwRJpoXLejtE0XfBDRy7VtM17OZ6hrwwnz2Ac5yB+gHxEAil 8Yy/o2dYMrqU/n+UY/It5tpevY7hQQCuR3lnqw8fPCLqGbMJ+/yIZzYQG5Lblv8+stHWaeomKnN uh/oPoe6QigdfhQUnFftuJwrFEhTf306Q4zhC4D3QfwsVk0UbtuRXh7bFKB7qbNqCDrmdS+gt1J /H+tVEgUHY9bopSZk0shLLN7eNccPpCuffGH9zI=
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/m-n60raXRCUF6cbOxUVB6n66Uys>
Subject: Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Jun 2023 15:36:11 -0000

>>> While policy advice on technical documents can certainly be helpful,
>>> it is simply not possible to provide useful policy advice without a
>>> clear understanding of the technology. That's how you end up with
>>> cryptographers repeatedly explaining why we can't put back doors in
>>> cryptosystems and policy people telling us we have to, just nerd
>>> harder.
>> 
>> Don't misunderstand me, I do think that backdoors in crypto are a bad
>> idea, but: is the cryptographers' explanation of why we can't have them
>> a technical or a policy argument? I always understood it as "if we do,
>> there is no way to eliminate the risk that they will fall into the wrong
>> hands", but whether that risk is acceptable or not and under which
>> conditions is a policy decision, not a technical one.
>
> I think this shows that there is not a separation between “policy” and
> “technology”.   Many (perhaps most) technology decisions are also
> policy decisions.   It doesn’t work to think that they are separate domains.   

It's an issue with the problem specification / requirements.
The technology is developed to address the spec.
If the spec says, "Don't allow anyone else to read the data," that is different from, "Generally keep it safe, but allow law enforcement to read it."

So, the problem definition is a policy thing.
The solution technology is just that: a solution.

The problem definition may need iteration with feedback from the technologists: "We cannot solve this problem as stated, because xyz. But we could solve it if you stated it like this or that."

Having wide input (user communities, societies, governments, et al.) on the problem statement is surely a good thing. It is kind of nice to be developing solutions that will make things people want to use.

Engineers, are, however, free to limit which projects they work on within the constraints of their governments.
Engineers' employers are, also within the constraints of their governments, free to choose how their staff spend their work time.

Adrian