Re: [hrpc] Fwd: draft-andersdotter (was RE: [Int-area] WG adoption call: Availability of Information in Criminal Investigations Involving Large-Scale IP Address Sharing Technologies

Vittorio Bertola <vittorio.bertola@open-xchange.com> Tue, 24 April 2018 13:58 UTC

Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: hrpc@ietfa.amsl.com
Delivered-To: hrpc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0161412D77D for <hrpc@ietfa.amsl.com>; Tue, 24 Apr 2018 06:58:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level:
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=open-xchange.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3SPbhLVwvDyY for <hrpc@ietfa.amsl.com>; Tue, 24 Apr 2018 06:58:51 -0700 (PDT)
Received: from mx4.open-xchange.com (alcatraz.open-xchange.com [87.191.39.187]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F624129BBF for <hrpc@irtf.org>; Tue, 24 Apr 2018 06:58:51 -0700 (PDT)
Received: from open-xchange.com (imap.open-xchange.com [10.20.30.10]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx4.open-xchange.com (Postfix) with ESMTPS id 26AFA6A309; Tue, 24 Apr 2018 15:58:49 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com; s=201705; t=1524578329; bh=6RNbTsvaVvpiLDMk/25GtQx+iWxHasXfVnz0Rg8EaYw=; h=Date:From:To:In-Reply-To:References:Subject:From; b=2z+cQSAFOXXbLcYawlXRjFZ/q55RNUvAEFJ5mfF3HzWBY9ZQMMh2LCyAQSxMt5M5c wOZeRlOMzW3ONmry8jyvIk0XbUFitttouLIL++xQKdpKSDr5CfeRJlYD5XM5hnc7p/ NfLzDWw3LGVpUgMxyi6ueQYWdLDvNVeorzVXfcAyxH3osyv3J6TQH9lzpy8cBjmYUt 38qNTpFyoC2d11us0h9Sq+ohwnB2x3SZn9kDW1YGWS6VxS6UFAEih9Df9/9x5AlYTW sKmmVeTBONWf7QErPaMygmZmgVhibZ2LdmJ8/b1KLcgOkKUPCUMK4+C2fDr4M3jn8F VjxK5UeGju2UQ==
Received: from null (appsuite-dev-gw2.open-xchange.com [10.20.30.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by open-xchange.com (Postfix) with ESMTPSA id 06D233C1C77; Tue, 24 Apr 2018 15:58:49 +0200 (CEST)
Date: Tue, 24 Apr 2018 15:56:12 +0200
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: Amelia Andersdotter <amelia@article19.org>, Hrpc <hrpc@irtf.org>
Message-ID: <1303956912.1157.1524578173059@appsuite-dev.open-xchange.com>
In-Reply-To: <d55b1de5-36b6-6e1e-b94e-918f36ab38b0@article19.org>
References: <787AE7BB302AE849A7480A190F8B93302DF0FAF6@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <d55b1de5-36b6-6e1e-b94e-918f36ab38b0@article19.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
X-Priority: 3
Importance: Medium
X-Mailer: Open-Xchange Mailer v7.10.0-Rev5
X-Originating-Client: open-xchange-appsuite
Archived-At: <https://mailarchive.ietf.org/arch/msg/hrpc/waXPaGj_N3CQq2Ma1dLrNVrb5aA>
Subject: Re: [hrpc] Fwd: draft-andersdotter (was RE: [Int-area] WG adoption call: Availability of Information in Criminal Investigations Involving Large-Scale IP Address Sharing Technologies
X-BeenThere: hrpc@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "mail@nielstenoever.net" <hrpc.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/hrpc>, <mailto:hrpc-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/hrpc/>
List-Post: <mailto:hrpc@irtf.org>
List-Help: <mailto:hrpc-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/hrpc>, <mailto:hrpc-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Apr 2018 13:58:53 -0000

> Il 23 aprile 2018 alle 10.52 Amelia Andersdotter <amelia@article19.org> ha scritto:
> 
> 
> Dear all,
> 
> join the fun over at int-area relating to this new draft:
> 
> https://datatracker.ietf.org/doc/draft-andersdotter-intarea-update-to-rfc6302/

Thanks, but I don't fancy one more flame on privacy vs operational/security needs. However, given the subject, maybe you could also be interested in the intermediate approach that we like to adopt when logging IP addresses in DNS resolvers:

https://medium.com/@bert.hubert/on-ip-address-encryption-security-analysis-with-respect-for-privacy-dabe1201b476

This does not remove the need to minimize data and destroy them as soon as possible, but adds one more data protection layer into the mix, so that pseudonymous analysis for operations and network security is possible with very limited privacy risks, while de-anonymized access is available through the appropriate company functions when actually necessary.

Regards,
-- 

Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
vittorio.bertola@open-xchange.com
Office @ Via Treviso 12, 10144 Torino, Italy