Re: Call for Adoption: draft-pauly-httpbis-geoip-hint

Poul-Henning Kamp <phk@phk.freebsd.dk> Tue, 06 September 2022 09:37 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DB21C1526ED for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 6 Sep 2022 02:37:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.662
X-Spam-Level:
X-Spam-Status: No, score=-7.662 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D7IfZrV0_Sej for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 6 Sep 2022 02:36:54 -0700 (PDT)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E0BA1C15256E for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 6 Sep 2022 02:36:54 -0700 (PDT)
Received: from lists by lyra.w3.org with local (Exim 4.94.2) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1oVUyJ-00FQDQ-Ms for ietf-http-wg-dist@listhub.w3.org; Tue, 06 Sep 2022 09:34:19 +0000
Resent-Date: Tue, 06 Sep 2022 09:34:19 +0000
Resent-Message-Id: <E1oVUyJ-00FQDQ-Ms@lyra.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by lyra.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <phk@critter.freebsd.dk>) id 1oVUyH-00FQCR-CR for ietf-http-wg@listhub.w3.org; Tue, 06 Sep 2022 09:34:17 +0000
Received: from phk.freebsd.dk ([130.225.244.222]) by mimas.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <phk@critter.freebsd.dk>) id 1oVUyF-00ADFw-Jx for ietf-http-wg@w3.org; Tue, 06 Sep 2022 09:34:17 +0000
Received: from critter.freebsd.dk (unknown [192.168.55.3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by phk.freebsd.dk (Postfix) with ESMTPS id 6D184892CD; Tue, 6 Sep 2022 09:34:02 +0000 (UTC)
Received: from critter.freebsd.dk (localhost [127.0.0.1]) by critter.freebsd.dk (8.16.1/8.16.1) with ESMTPS id 2869Y1Fp066082 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NO); Tue, 6 Sep 2022 09:34:01 GMT (envelope-from phk@critter.freebsd.dk)
Received: (from phk@localhost) by critter.freebsd.dk (8.16.1/8.16.1/Submit) id 2869Y0hg066081; Tue, 6 Sep 2022 09:34:00 GMT (envelope-from phk)
Message-Id: <202209060934.2869Y0hg066081@critter.freebsd.dk>
To: Mark Nottingham <mnot@mnot.net>
cc: HTTP Working Group <ietf-http-wg@w3.org>
In-reply-to: <694DD6A2-5191-488C-8A93-FE670992204D@mnot.net>
From: Poul-Henning Kamp <phk@phk.freebsd.dk>
References: <694DD6A2-5191-488C-8A93-FE670992204D@mnot.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-ID: <66079.1662456840.1@critter.freebsd.dk>
Content-Transfer-Encoding: quoted-printable
Date: Tue, 06 Sep 2022 09:34:00 +0000
Received-SPF: pass client-ip=130.225.244.222; envelope-from=phk@critter.freebsd.dk; helo=phk.freebsd.dk
X-W3C-Hub-Spam-Status: No, score=-4.9
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, W3C_AA=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1oVUyF-00ADFw-Jx c768cf05c7e100c99327a84335b33457
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for Adoption: draft-pauly-httpbis-geoip-hint
Archived-At: <https://www.w3.org/mid/202209060934.2869Y0hg066081@critter.freebsd.dk>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/40376
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

--------
Mark Nottingham writes:

> At IETF 114, we saw some interest in adding hints about the client's 
> location to requests in certain circumstances, with the condition that 
> it be done in a way that doesn't compromise privacy. 

There are two different scopes to this topic:

* "Jurisdictional" - is the client subject to this or that law, jurisdiction or regulation.

* "Informational" - pretty much everything else.

There are all sorts of unholy regulation bubbling under the surface
with respect to the first one, because politicians, justifiably,
have become really keen on being able to tell genuine citizens apart
from (foreign-controlled) bots and sock-puppets, and in parallel,
protecting children from content which violate "community standards".

The main argument for exchanging such information at our level in the
stack is that it will reduce the need for actual, and much more
privacy-leaking, user authentication.

Despite that, it is still a minefield, political, cryptographically
and technically, which I think we should stay very clear from.

Mark writes "certain circumstances" and "doesn't compromise privacy",
but to increase chances of success, I think we need to be much more
clear about our intentions.

I propose that we make it 100% clear up front, even before adopting
this or any other proposal, that any information provided via the
mechanism we (might) come up with, does not, and can not, carry any
legal weight or message, because it SHALL be 100% up to the users
whims and discretion, and that it SHALL be opt-out by default.

-- 
Poul-Henning Kamp       | UNIX since Zilog Zeus 3.20
phk@FreeBSD.ORG         | TCP/IP since RFC 956
FreeBSD committer       | BSD since 4.3-tahoe    
Never attribute to malice what can adequately be explained by incompetence.