Re: [ietf-privacy] [Int-area] NAT Reveal / Host Identifiers

David Singer <singer@apple.com> Mon, 09 June 2014 13:34 UTC

Return-Path: <singer@apple.com>
X-Original-To: ietf-privacy@ietfa.amsl.com
Delivered-To: ietf-privacy@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 635B11A0174 for <ietf-privacy@ietfa.amsl.com>; Mon, 9 Jun 2014 06:34:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.652
X-Spam-Level:
X-Spam-Status: No, score=-2.652 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dnUVxKPtQV8p for <ietf-privacy@ietfa.amsl.com>; Mon, 9 Jun 2014 06:34:55 -0700 (PDT)
Received: from mail-in5.apple.com (mail-out5.apple.com [17.151.62.27]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F1C31A0168 for <ietf-privacy@ietf.org>; Mon, 9 Jun 2014 06:34:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=apple.com; s=mailout2048s; c=relaxed/simple; q=dns/txt; i=@apple.com; t=1402320894; x=2266234494; h=From:Sender:Reply-To:Subject:Date:Message-id:To:Cc:MIME-version:Content-type: Content-transfer-encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-reply-to:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=QnbRHygrfiJK74Hh1uWrA41qTXFc1h7KevMfV/Wx18k=; b=v/rzA4w4x+MIo5ojxMXpMSwB1iT5tz759Z0Jkhb/SQeTeBq7bH0sl29ksnMNZouq 9A4BJcDeVXooGyrjkR9YBOxQ00FdENCJTNH3KlQyn/10jK7Ic16iZM/ZAJUIeCSn LctZ/lfrLQm6qNogr9Tl86DYWowSD7NNUh+tKmjzhtHXOitT+/klTC6fnsdIzDmK Ud97HafJJE2BoBtR5/173wOTTX8Ts/upkPvMnQDKAjng8v16cFxcyzgYt2UvfaZB r1WWwWR4u4laznj9Mzqy7WWt6pCoeklcxp+1sAK+k2bx/Sitw9kzmEE7ZQrmHSAY FIYSX48Q42IY1y0E0t0kTQ==;
Received: from mail-out.apple.com (honeycrisp.apple.com [17.151.62.51]) (using TLS with cipher RC4-MD5 (128/128 bits)) (Client did not present a certificate) by mail-in5.apple.com (Apple Secure Mail Relay) with SMTP id 10.BF.08063.EF7B5935; Mon, 9 Jun 2014 06:34:54 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; CHARSET=US-ASCII
Received: from relay4.apple.com ([17.128.113.87]) by local.mail-out.apple.com (Oracle Communications Messaging Server 7.0.5.30.0 64bit (built Oct 22 2013)) with ESMTP id <0N6W00FM0LP1DA51@local.mail-out.apple.com>; Mon, 09 Jun 2014 06:34:54 -0700 (PDT)
X-AuditID: 11973e13-f79d56d000001f7f-ca-5395b7fe88c7
Received: from fenugreek.apple.com (fenugreek.apple.com [17.128.115.97]) (using TLS with cipher RC4-MD5 (128/128 bits)) (Client did not present a certificate) by relay4.apple.com (Apple SCV relay) with SMTP id C9.C5.03493.108B5935; Mon, 9 Jun 2014 06:34:57 -0700 (PDT)
Received: from [17.153.19.22] (unknown [17.153.19.22]) by fenugreek.apple.com (Oracle Communications Messaging Server 7.0.5.30.0 64bit (built Oct 22 2013)) with ESMTPSA id <0N6W00MVZLQ38F60@fenugreek.apple.com>; Mon, 09 Jun 2014 06:34:54 -0700 (PDT)
From: David Singer <singer@apple.com>
In-reply-to: <82A0BCB8-F77C-4C8B-9769-BF4EE2F748A0@isi.edu>
Date: Mon, 09 Jun 2014 09:34:51 -0400
Message-id: <747229F0-D5EB-4262-B14C-46C860F9165C@apple.com>
References: <E87B771635882B4BA20096B589152EF628724B2C@eusaamb107.ericsson.se> <539016BE.3070008@gmx.net> <53906711.5070406@cs.tcd.ie> <5390CEC9.3000005@isi.edu> <5D2CC7D6-D9E1-49A8-818C-5FB33DC283C0@cisco.com> <5393119F.6050805@cs.tcd.ie> <82A0BCB8-F77C-4C8B-9769-BF4EE2F748A0@isi.edu>
To: Joe Touch <touch@ISI.EDU>
X-Mailer: Apple Mail (2.1878.2)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrMLMWRmVeSWpSXmKPExsUiON3OWPff9qnBBqsOm1ocvtrAbnFj1k0W ByaPJUt+MgUwRnHZpKTmZJalFunbJXBlrJmdV7CXqWLBjfvMDYxfGbsYOTkkBEwkJm6aB2WL SVy4t56ti5GLQ0hgDpNEz9s+sASvgKDEj8n3WLoYOTiYBeQlDp6XBQkzC2hJfH/UygJR38Qk MfHjOTaYoU2TPrJDJCYzSdy7tRRqaiOTxN9zu5lAJgkLuErM/Z8M0sAmoCrxYM4xsGWcAtYS jR83sYDYLEDxo2degw1iFmhnlLjUcYQJ4iIbiYdrDjFCDF3MJPFibTfYahEBWYnG3d9YIc6Q l5jRfgKsW0LgN6vEz+sfmCcwisxC8tIshJdmIXlpASPzKkah3MTMHN3MPFO9xIKCnFS95Pzc TYyQUBfewXh6ldUhRgEORiUe3ojfU4KFWBPLiitzDzFKc7AoifMyFEwKFhJITyxJzU5NLUgt ii8qzUktPsTIxMEp1cAYvMDrxaTrd0rvKCZzGYoejnpsOMex4n5dqMmxpWLAGA2UfnVNzt3m 5DrxqL/6v7NXfP/GJSg26Zvvyqf9i07nLrcwl0h5L1ymEc967fDGyb1KqplHP6/QtGCxnaIX pP5AqPv3KZbO7+fOvEmccHUB17zdUw7YBPpXTJw1vd5vln/f0skmt4KVWIozEg21mIuKEwE5 imsFVgIAAA==
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrNLMWRmVeSWpSXmKPExsUi2FCcqMu4Y2qwQfM8FovDVxvYLW7Musni wOSxZMlPpgDGKC6blNSczLLUIn27BK6Mb1uvMhYcYKp413WXqYHxG2MXIyeHhICJRNOkj+wQ tpjEhXvr2UBsIYHJTBJdewq7GLmA7EYmib/ndjOBJJgFtCTW7zwOZvMKGEi8OQhic3AIC7hK zP2fDBJmE1CVeDDnGNh8TgFricaPm1hAbBag+NEzr9lBZjILtDNKXOo4AjVTW+LJuwusEDNt JB6uOcQIsXgxk8SLtd1gF4kIyEo07v7GCnGpvMSM9hPsExgFZiG5aRaSm2YhmbuAkXkVo0BR ak5ipYleYkFBTqpecn7uJkZwEBaG72D8t8zqEKMAB6MSD2/E7ynBQqyJZcWVuYcYJTiYlUR4 O9ZPDRbiTUmsrEotyo8vKs1JLT7EKM3BoiTOK757QrCQQHpiSWp2ampBahFMlomDU6qB8eTB iUzscz0aPuzMubLkz85Tx23N58arf3bMql17cVV67rbqR3Pe7rba+cL1cvWzZT+yhCsYa97K n2hewdoX3zP37IU97ZLGK97/8DzIsNNzVXvgDGHBg7m8t7vL7K4fbdS8tlOn3v/r5g3bZP9L yvQceR728qZa6lOjq02hjHM0jb52FBYcW6HEUpyRaKjFXFScCACemg3vPgIAAA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf-privacy/uFTv5Vy4ynYcEfRnVBV1jZV-NiU
Cc: "ietf-privacy@ietf.org" <ietf-privacy@ietf.org>, Internet Area <int-area@ietf.org>
Subject: Re: [ietf-privacy] [Int-area] NAT Reveal / Host Identifiers
X-BeenThere: ietf-privacy@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Internet Privacy Discussion List <ietf-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-privacy>, <mailto:ietf-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf-privacy/>
List-Post: <mailto:ietf-privacy@ietf.org>
List-Help: <mailto:ietf-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-privacy>, <mailto:ietf-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Jun 2014 13:34:57 -0000

On Jun 8, 2014, at 20:26 , Joe Touch <touch@ISI.EDU> wrote:

> 	a NAT hides the host *at the expense* of exposing a router

If I have the energy to do a DoS attack, surely I have the energy to traceroute the hosts I know to find a common routing point?

David Singer
Manager, Software Standards, Apple Inc.