[Geopriv] Serious concerns about security of draft-ietf-geopriv-held-identity-extensions

Cullen Jennings <fluffy@cisco.com> Sun, 08 November 2009 04:28 UTC

Return-Path: <fluffy@cisco.com>
X-Original-To: geopriv@core3.amsl.com
Delivered-To: geopriv@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 132323A68CB for <geopriv@core3.amsl.com>; Sat, 7 Nov 2009 20:28:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.231
X-Spam-Level:
X-Spam-Status: No, score=-106.231 tagged_above=-999 required=5 tests=[AWL=0.369, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3h-n8AuDmSry for <geopriv@core3.amsl.com>; Sat, 7 Nov 2009 20:28:00 -0800 (PST)
Received: from sj-iport-5.cisco.com (sj-iport-5.cisco.com [171.68.10.87]) by core3.amsl.com (Postfix) with ESMTP id 5E30D3A684C for <geopriv@ietf.org>; Sat, 7 Nov 2009 20:28:00 -0800 (PST)
Authentication-Results: sj-iport-5.cisco.com; dkim=neutral (message not signed) header.i=none
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: ApoEANrX9UpAaHte/2dsb2JhbADCXJcIgjmCBQSCYA
X-IronPort-AV: E=Sophos;i="4.44,702,1249257600"; d="scan'208";a="102934490"
Received: from hkg-core-1.cisco.com ([64.104.123.94]) by sj-iport-5.cisco.com with ESMTP; 08 Nov 2009 04:28:25 +0000
Received: from tky-vpn-client-231-209.cisco.com (tky-vpn-client-231-209.cisco.com [10.70.231.209]) by hkg-core-1.cisco.com (8.13.8/8.14.3) with ESMTP id nA84SNTn028453 for <geopriv@ietf.org>; Sun, 8 Nov 2009 04:28:24 GMT
From: Cullen Jennings <fluffy@cisco.com>
Content-Type: text/plain; charset="us-ascii"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Date: Sun, 08 Nov 2009 13:28:23 +0900
Message-Id: <CEBE292E-A612-4BE8-A2F0-5AF955BF23A3@cisco.com>
To: GEOPRIV <geopriv@ietf.org>
Mime-Version: 1.0 (Apple Message framework v1076)
X-Mailer: Apple Mail (2.1076)
Subject: [Geopriv] Serious concerns about security of draft-ietf-geopriv-held-identity-extensions
X-BeenThere: geopriv@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Geographic Location/Privacy <geopriv.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/geopriv>, <mailto:geopriv-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/geopriv>
List-Post: <mailto:geopriv@ietf.org>
List-Help: <mailto:geopriv-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/geopriv>, <mailto:geopriv-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Nov 2009 04:28:01 -0000

I really hope we get some discussion on this at this meeting. Take for  
example using a MAC address as an identifier. A request arrives and  
requests the location of device with a given MAC. How does  the server  
know if it should answer this or not? If it has an IP to MAC mapping,  
why did it need the MAC, and why not use use IP.

I don't think the answer can be it knows due to something that will  
described some time later. That answer seems like it would not meet  
the IETF goals of security that can be implemented (even it it is not  
used) or the general charter of this WG.

I don't understanding how the privacy part of this is protected. I  
need to understand that or I worry that this work is not appropriate  
for geopriv WG.

Cullen <in my RAI AD role>