Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders

John R Levine <johnl@taugh.com> Thu, 22 June 2023 16:23 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8EBA0C16B5D6 for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 09:23:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b="ulel3Chf"; dkim=pass (2048-bit key) header.d=taugh.com header.b="OA6J5Obp"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TsOlqod0Oqzv for <gendispatch@ietfa.amsl.com>; Thu, 22 Jun 2023 09:23:20 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A000BC16B5D4 for <gendispatch@ietf.org>; Thu, 22 Jun 2023 09:23:19 -0700 (PDT)
Received: (qmail 95247 invoked from network); 22 Jun 2023 16:23:17 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=iecc.com; h=date:message-id:from:to:subject:in-reply-to:references:mime-version:content-type; s=1740d.64947575.k2306; bh=cPImwGbJQ+lrZqfqTIqFT2rDBcPHQ0QbDHfx3QmiP7o=; b=ulel3Chf6si/RBTjpZFjoOX60JDjgELvDEttfxKdC2NutfxP/sc+ap969V8MR3BSHF0iFCI3HIPGdlE60Y40eHhijplutNjMnJY0A6hpg1hgCZzs2YUtL6RZfmFb4y0mQdHL4wX1KFRXLddxLtWNtBKKwqWjVDUJTBWQn9PdYWReR5Pv9ERCo11EuIg184qUMEWyjjzMN0MYA+0V0QD72Np6iwKnFuD9bqmyqHZ1kRB3ljYZx56VLCnze+nIfIQYJ1Ebt6iJO1cI+t962edKbimny/cZPfyo/Tkx1boLjWzsEbHd+RDUBQODA3rY6Vs+vBoCJx0yQJufbVLJIeb+5g==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=taugh.com; h=date:message-id:from:to:subject:in-reply-to:references:mime-version:content-type; s=1740d.64947575.k2306; bh=cPImwGbJQ+lrZqfqTIqFT2rDBcPHQ0QbDHfx3QmiP7o=; b=OA6J5ObpZ0qAGKb5ILTUanZRO5kIsGh+MIw5jDrjFhAqel5tRFyF++GUX4zBF+LDHsPkvt+SdMVw1jc9NVNyI9V74O24y/6nUS7nuiMrGp4vH/yNceTWMjbOuSANGmrjXcCrmnDT8ujw1FBrapTiS/YnEVbwYErUk50Ev3J1U7CP/DL66lbbSipsiBSZcfo+2z3pPRlG6pgI4y98tBHoZn8uRTIQV9Hjfs7ewTexfqOuMP1qFcmzF3JsAOF5mu9L/U74AkZdZ04BBIbLQ9uhiekB/ukCOK7wMhun2kTdoc3zmlRBGEwI23TDjNZ4eqSRTHnQto67W/mCKS23/fBniA==
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.3 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 22 Jun 2023 16:23:16 -0000
Received: by ary.qy (Postfix, from userid 501) id 6DB2AF959A09; Thu, 22 Jun 2023 12:23:15 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by ary.qy (Postfix) with ESMTP id 5C957F959A07; Thu, 22 Jun 2023 12:23:15 -0400 (EDT)
Date: Thu, 22 Jun 2023 12:23:15 -0400
Message-ID: <59b7283c-1ea7-82ea-35da-28b659a27fb5@taugh.com>
From: John R Levine <johnl@taugh.com>
To: Vittorio Bertola <vittorio.bertola@open-xchange.com>, gendispatch@ietf.org
X-X-Sender: johnl@ary.qy
In-Reply-To: <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com>
References: <6b349547-a26b-4028-14a7-6be3f3e44321@huitema.net> <20230620163302.ACBA8F6FA18F@ary.qy> <231861687.27760.1687420035913@appsuite-gw1.open-xchange.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"; charset="us-ascii"
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/zVuNKoOgDLfB2O-DjmBRvo8FQIk>
Subject: Re: [Gendispatch] Updated draft: Policy experts are IETF stakeholders
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Jun 2023 16:23:25 -0000

On Thu, 22 Jun 2023, Vittorio Bertola wrote:
>> clear understanding of the technology. That's how you end up with
>> cryptographers repeatedly explaining why we can't put back doors in
>> cryptosystems and policy people telling us we have to, just nerd
>> harder.
>
> Don't misunderstand me, I do think that backdoors in crypto are a bad 
> idea, but: is the cryptographers' explanation of why we can't have them 
> a technical or a policy argument? I always understood it as "if we do, 
> there is no way to eliminate the risk that they will fall into the wrong 
> hands", but whether that risk is acceptable or not and under which 
> conditions is a policy decision, not a technical one.

I think it's more a persistent misunderstanding of what the risks are.

Law enforcement has a century of experience with wiretaps.  They have a 
gradual failure model.  If I lie to a judge or bribe a phone tech, I can 
get taps on a few phone lines but I can't listen in to the entire phone 
system.  As we all know, software isn't like that, often fails 
catastrophically, and we have no way to ensure any particular piece of 
software doesn't have catastrophic bugs.  Putting the software in hardware 
doesn't help.  The 1990s Clipper chip which was supposed to provide a 
controlled key escrow designed by the NSA turned out to have bugs that 
made it easy to evode the escrow.

Phill recently sent a message listing the impossible set of questions 
you'd have to answer to build a backdoored system.  But if you believe 
that the wiretap model is the way things work, you don't have to answer 
any of those questions.  You just have to tell the nerds to nerd harder 
and build something that fails like wiretaps do.

So far we have largely failed to get policy people to understand the way 
software fails and how to evaluate its risks.  To some extent that's 
because they don't want to, but there's not much we can do about that.

Blog post here: https://jl.ly/Internet/catastrophe.html

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly