Re: [Ietf-and-github] AD review of draft-ietf-git-github-wg-configuration-05
Alissa Cooper <alissa@cooperw.in> Mon, 10 February 2020 14:43 UTC
Return-Path: <alissa@cooperw.in>
X-Original-To: ietf-and-github@ietfa.amsl.com
Delivered-To: ietf-and-github@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id A42DF12022C;
Mon, 10 Feb 2020 06:43:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001,
URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=cooperw.in header.b=QabUA5/r;
dkim=pass (2048-bit key)
header.d=messagingengine.com header.b=VdhVvEXZ
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 1jzDkkbMz0tC; Mon, 10 Feb 2020 06:43:04 -0800 (PST)
Received: from out5-smtp.messagingengine.com (out5-smtp.messagingengine.com
[66.111.4.29])
(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id F178E120227;
Mon, 10 Feb 2020 06:43:03 -0800 (PST)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47])
by mailout.nyi.internal (Postfix) with ESMTP id 0D5AB21F85;
Mon, 10 Feb 2020 09:43:03 -0500 (EST)
Received: from mailfrontend1 ([10.202.2.162])
by compute7.internal (MEProxy); Mon, 10 Feb 2020 09:43:03 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cooperw.in; h=
content-type:mime-version:subject:from:in-reply-to:date:cc
:content-transfer-encoding:message-id:references:to; s=fm2; bh=Q
MTUXoMGSb+5eIkE22EbAJnBSWeq7WhRZT+BWVF8p80=; b=QabUA5/rVcLmhdaOf
9Bu/jht4RLS0DSvTanajiKIcg4vvw06aYQzyN891McSZmtQsQ/tmuRw8GMSfVb8p
dUadjYdPISMKEoqFpCtrxgJA8LdmLeg4N0zwkF3IVo/J7o9YoFZ+2dn0ks3UOfrW
nCh2na3zKO15D+koxHPF9oxAotv3b6o3uP888iC9whUl43yOguByMEXIGvcJWrqP
IPGt7Euz3ScWsC/PUL3i3bbW+Ek1bH8NuouizyLRVB/PNdTdsSAD9sjsWmW4sLZ+
Y32SoPnpsAlkVFmZ9LDyQu4i1UN+L+8zABSFEuYEiBf1mdj+1B4k7NmIjGkucU6d
ouRAw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
messagingengine.com; h=cc:content-transfer-encoding:content-type
:date:from:in-reply-to:message-id:mime-version:references
:subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender
:x-sasl-enc; s=fm2; bh=QMTUXoMGSb+5eIkE22EbAJnBSWeq7WhRZT+BWVF8p
80=; b=VdhVvEXZmMK6qVimOa8id40RVAR6/FGvAnKFlE7Ziw6zyPwE0hu1G/SA6
7kGJ5BhmFe1rDN50QXwbm9RhcQTyITHq30l28ZwaAsoHSOckrcJ2mIYBPnXPa8/E
QCBzQ34hxMpqP/tgWLWRsxr7hd4WVZjRGflHY0bm5pCOqXy6EqBmG677X8INuKd9
gspsZLkX56Yqke6mYfJIYpZ34ENY6THUekD/IUnh3cAYOf2mUgS4hh+Lw8crao7Y
jiRIGsZa2eBiy51TZNQ1KM93T96hDhQSWRQCwQO3YiYmKgyo6SAHYB47jCvqyZIR
3dh+lPKZ8UTpDStOY3liacxcWFw/g==
X-ME-Sender: <xms:9mtBXgNqdrZg-wq0D36STUkLWDLnIUkNV6-d1Ap355Ii3w71zaDtKA>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedugedriedugdeihecutefuodetggdotefrodftvf
curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu
uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc
fjughrpegtggfuhfgjfffgkfhfvffosehtqhhmtdhhtdejnecuhfhrohhmpeetlhhishhs
rgcuvehoohhpvghruceorghlihhsshgrsegtohhophgvrhifrdhinheqnecuffhomhgrih
hnpehivghtfhdrohhrghenucfkphepudejfedrfeekrdduudejrdeltdenucevlhhushht
vghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpegrlhhishhsrgestghooh
hpvghrfidrihhn
X-ME-Proxy: <xmx:9mtBXj2qi-9ArUZiG7FfxEDuRqTz3ROffOMRH3satkQO085WGdDLfA>
<xmx:9mtBXnD_Ml3y4FIhgXcvt4SdSmO59wDLlcJXT-B7XfyNHakRRQGDFw>
<xmx:9mtBXoKS9Zz9-MnxbqiWN09-8ou85H9pJk00ps3YOzRlXUNHQequ5g>
<xmx:92tBXmerH09fpVrxwqN3-US_iymz2v9oyKfP8Y759N2zIU_jRkor0w>
Received: from rtp-alcoop-nitro2.cisco.com (unknown [173.38.117.90])
by mail.messagingengine.com (Postfix) with ESMTPA id 92ECB3280063;
Mon, 10 Feb 2020 09:43:02 -0500 (EST)
Content-Type: text/plain;
charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Alissa Cooper <alissa@cooperw.in>
In-Reply-To: <CALaySJLuEDETWX6QTS4YmoqBPMf+7H+39cy9E5JYT=6f+8cY4A@mail.gmail.com>
Date: Mon, 10 Feb 2020 09:43:00 -0500
Cc: draft-ietf-git-github-wg-configuration@ietf.org, git-chairs@ietf.org,
ietf-and-github@ietf.org, caw@heapingbits.net
Content-Transfer-Encoding: quoted-printable
Message-Id: <DBE842DE-75C2-41B9-B7C2-C2CFE366F5A5@cooperw.in>
References: <CALaySJLuEDETWX6QTS4YmoqBPMf+7H+39cy9E5JYT=6f+8cY4A@mail.gmail.com>
To: Barry Leiba <barryleiba@computer.org>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-and-github/M2GFtL2pBXdf4PSr52clO51hiiA>
Subject: Re: [Ietf-and-github] AD review of
draft-ietf-git-github-wg-configuration-05
X-BeenThere: ietf-and-github@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of using GitHub in IETF activities,
particularly for Working Groups" <ietf-and-github.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-and-github>,
<mailto:ietf-and-github-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-and-github/>
List-Post: <mailto:ietf-and-github@ietf.org>
List-Help: <mailto:ietf-and-github-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-and-github>,
<mailto:ietf-and-github-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Feb 2020 14:43:06 -0000
Hi Barry, Thanks. One comment below. > On Feb 7, 2020, at 11:30 AM, Barry Leiba <barryleiba@computer.org> wrote: > > — Section 2.5 — > > o Creating a new repository for an individual draft that is at the > discretion of the WG chair; > > What does “an individual draft that is at the discretion of the WG chair” mean? Would it be clearer to say "Creating a new repository for an individual draft (at the discretion of the WG chair);”? Best, Alissa > > — Section 4 — > > An attacker who can change the contents of Internet Drafts, > particularly late in a working group's process, can possibly cause > unnoticed changes in protocols that are eventually adopted. > > Indeed, and so should we propose any mitigations? Using a github > instance that’s maintained and secured under ietf.org? At the very > least we’ll need to rely on careful review during the publication > process, including verifying what changes were made at each step and > flagging questionable changes. The text here should probably say > something more. > > -- > Barry > > _______________________________________________ > Ietf-and-github mailing list > Ietf-and-github@ietf.org > https://www.ietf.org/mailman/listinfo/ietf-and-github
- [Ietf-and-github] AD review of draft-ietf-git-git… Barry Leiba
- Re: [Ietf-and-github] AD review of draft-ietf-git… Christopher Wood
- Re: [Ietf-and-github] AD review of draft-ietf-git… Alissa Cooper
- Re: [Ietf-and-github] AD review of draft-ietf-git… Barry Leiba