Re: [hybi] A bit of pragmatism / intermediary triage

Bruce Atherton <bruce@callenish.com> Sun, 09 January 2011 21:14 UTC

Return-Path: <bruce@callenish.com>
X-Original-To: hybi@core3.amsl.com
Delivered-To: hybi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0A6D928C0D8 for <hybi@core3.amsl.com>; Sun, 9 Jan 2011 13:14:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.58
X-Spam-Level:
X-Spam-Status: No, score=-2.58 tagged_above=-999 required=5 tests=[AWL=0.019, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5MX6Sq4TE67D for <hybi@core3.amsl.com>; Sun, 9 Jan 2011 13:14:07 -0800 (PST)
Received: from biz82.inmotionhosting.com (biz82.inmotionhosting.com [74.124.202.87]) by core3.amsl.com (Postfix) with ESMTP id 581B128C0D0 for <hybi@ietf.org>; Sun, 9 Jan 2011 13:14:07 -0800 (PST)
Received: from [24.108.133.142] (helo=[192.168.145.101]) by biz82.inmotionhosting.com with esmtpa (Exim 4.69) (envelope-from <bruce@callenish.com>) id 1Pc2cc-0007F3-8e for hybi@ietf.org; Sun, 09 Jan 2011 13:16:18 -0800
Message-ID: <4D2A25A1.7010909@callenish.com>
Date: Sun, 09 Jan 2011 13:16:17 -0800
From: Bruce Atherton <bruce@callenish.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.13) Gecko/20101207 Lightning/1.0b2 Thunderbird/3.1.7
MIME-Version: 1.0
To: "hybi@ietf.org" <hybi@ietf.org>
References: <AANLkTimetuh1H6OCg_rHZHe16im1bHCwSJFYWTeDbNwx@mail.gmail.com> <20110106221426.GA28367@1wt.eu> <AANLkTimNc6YDUG=920P=G7kxs9oDwDEsGJ5LA6BG_iyb@mail.gmail.com> <20110107053410.GG28367@1wt.eu> <AANLkTinQADv+iq50=dsvK13cu1YdS5sb+xHvDZnfdOjB@mail.gmail.com> <20110107061043.GJ28367@1wt.eu> <AANLkTikHXQza-gx=tqD7jZ+ueQZTXa9acRVG+bBfdApG@mail.gmail.com> <20110107063854.GN28367@1wt.eu> <4D26D20C.8030906@warmcat.com> <10468.1294391783.740346@puncture> <20110107100313.GO28367@1wt.eu> <10468.1294398928.011152@puncture> <4D28AE05.4070500@callenish.com> <4D28BD89.70704@warmcat.com> <4D28FD92.60803@callenish.com> <4D29A145.1080003@warmcat.com>
In-Reply-To: <4D29A145.1080003@warmcat.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - biz82.inmotionhosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - callenish.com
Subject: Re: [hybi] A bit of pragmatism / intermediary triage
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 09 Jan 2011 21:14:08 -0000

On 09/01/2011 3:51 AM, Andy Green wrote:
>
> Bruce, you are the guy who handwaved about "known vulnerability" on 
> the list so it is you I replied to on the list.
>

I did say that this is a known vulnerability. I did not say that it is a 
valid vulnerability to worry about. Whether it is or it isn't, I don't 
know and I don't care because what I think doesn't matter in this instance.

I see a lot of people get frustrated on this list because they think 
that the point of the discussion is to present the best technical 
argument. It isn't. The point is to persuade other people about the best 
technical argument. And the people who ship web browsers have all said 
that they are not persuaded by the types of arguments you have presented.

Andy, I can understand your frustration, but it isn't helping anything. 
The decision has been made via the straw poll to use masking in the 
protocol. Let's put this to rest now, please.