RE: Proposed Statement on "HTTPS everywhere for the IETF"

"Tony Hain" <alh-ietf@tndh.net> Wed, 03 June 2015 21:04 UTC

Return-Path: <alh-ietf@tndh.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 704CC1B2D98; Wed, 3 Jun 2015 14:04:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.801
X-Spam-Level:
X-Spam-Status: No, score=-1.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fS-imxykUfD2; Wed, 3 Jun 2015 14:04:12 -0700 (PDT)
Received: from express.tndh.net (express.tndh.net [IPv6:2001:470:e930:1240:20d:56ff:fe04:4c0a]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 058F61B2D94; Wed, 3 Jun 2015 14:04:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tndh.net; s=dkim; h=Subject:Content-Transfer-Encoding:Content-Type:MIME-Version:Message-ID:Date:In-Reply-To:References:To:From; bh=KCQOno4dPmEz/ag2Auyrqi7VBPfA8PCyeG5lcfUQTSk=; b=AjYL0xGXyIqjgz6DXR35a8pjf5WWycfo5qd0U0MnT0DRQkz+3yhy/WuaH4hoEGnADWjCT1c6ilUeylNpQiLnOI460vUaIJZ03xcocKorEOAn5FKzZbqmG+bIYlno3dX6rYqiEHRFyoVBwuYqmwad3zIDJv/T4LaRXKt4eYIiEB8uMBCv;
Received: from express.tndh.local ([2001:470:e930:1240:20d:56ff:fe04:4c0a] helo=eaglet) by express.tndh.net with esmtp (Exim 4.72 (FreeBSD)) (envelope-from <alh-ietf@tndh.net>) id 1Z0FpN-0003VL-UB; Wed, 03 Jun 2015 14:04:09 -0700
From: Tony Hain <alh-ietf@tndh.net>
To: 'Stephen Farrell' <stephen.farrell@cs.tcd.ie>, ietf@ietf.org, 'IETF Announcement List' <ietf-announce@ietf.org>
References: <20150601164359.29999.35343.idtracker@ietfa.amsl.com> <0ab501d09e37$f4098980$dc1c9c80$@tndh.net> <556F6083.4080801@cs.tcd.ie>
In-Reply-To: <556F6083.4080801@cs.tcd.ie>
Date: Wed, 03 Jun 2015 14:03:59 -0700
Message-ID: <0adf01d09e40$cf957b00$6ec07100$@tndh.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQEOzNU1RqxCT3Y5GM1VnUp3WH8IOAILo+5xA0TRpzye9GAJYA==
Content-Language: en-us
X-SA-Exim-Connect-IP: 2001:470:e930:1240:20d:56ff:fe04:4c0a
X-SA-Exim-Mail-From: alh-ietf@tndh.net
Subject: RE: Proposed Statement on "HTTPS everywhere for the IETF"
X-SA-Exim-Version: 4.2
X-SA-Exim-Scanned: Yes (on express.tndh.net)
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/0EjGagyoT8t4qntVcGsOIJJsSmo>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Jun 2015 21:04:13 -0000

Stephen Farrell wrote:
> Hi,
> 
> On 03/06/15 21:00, Tony Hain wrote:
> > While I don't object to making the IETF content available via
> > https/tls,
> 
> That's been done for ages. This just makes it the default. Which does
> require some minor changes.
> 
> > this proposed statement reads as political knee-jerk BS that is both
> > unnecessary and uncalled for. What the statement MUST focus on is
> > 'data integrity', and SHOULD NOT stoop to fear mongering over
> > 'privacy'.
> 
> I have to say the above seems somewhat overstated. (Where my use of
> "somewhat" is understatement:-)

How is taking a position that technical accuracy of the IETF content is critical an overstatement? 

> 
> > "It is public data ..." For the very small subset that is truly
> > restricted access, it is fine to acknowledge 'privacy'
> > as a concern, but for the vast majority of the content in question,
> > 'data integrity' is the only real concern.
> 
> I would assert that the existence of the dprive WG is good evidence that the
> IETF does not consider data-integrity as the only real concern for public
> data.

And I would assert that it shows a group-think knee-jerk overreaction to threats that hypothetically could be applied in broader contexts than history documents. We are both free to express our own assertions.

> 
> I'd also note that there is no TLS ciphersuite that satisfies BCP195 and that
> only provides data integrity. That very recent IETF consensus document says
> one MUST NOT negotiate any of the ciphersuites with NULL encryption
> (essentially outside of testing/debug). So what you appear to want this
> statement to say would seem to be inconsistent with IETF consensus.

I never argued FOR null encryption. My point was that 'privacy' is not a technical need in this case. It may come about as a side effect, but the proposed statement as written is not focused on the technical requirement of the IETF. It is instead a political statement that has no technical justification based on the needs of the community. To be clear, the technical need is data integrity. The implementation MAY provide privacy, and given current technologies likely will. 

Tony


> 
> Cheers,
> S.
> 
> 
> >
> > As such, I oppose the statement as written. Fix the tone and I will be
> > a strong supporter.
> >
> > Tony
> >
> >
> >> -----Original Message----- From: IETF-Announce
> >> [mailto:ietf-announce-bounces@ietf.org] On Behalf Of The IESG Sent:
> >> Monday, June 01, 2015 9:44 AM To: IETF Announcement List Subject:
> >> Proposed Statement on "HTTPS everywhere for the IETF"
> >>
> >> Hi All,
> >>
> >> The IESG are planning to agree an IESG statement on "HTTPS Everywhere
> >> for the IETF," please see [1] for the current text.
> >>
> >> We are seeking community feedback on this and welcome assistance
> from
> >> the community in identifying any cases where a change or additional
> >> guidance is needed to put this into effect.
> >>
> >> The IESG plans to finalise this statement just after IETF-93 in
> >> Prague.
> >>
> >> * Please send general feedback intended for discussion to
> >> ietf@ietf.org
> >>
> >> * Comments about specific issues arising can be sent to iesg@ietf.org
> >> or tools-discuss@ietf.org as appropriate (use iesg@ietf.org if not
> >> sure)
> >>
> >> Regards, Terry & Stephen (for the IESG)
> >>
> >> [1]
> >> https://trac.tools.ietf.org/group/iesg/trac/wiki/HttpsEverywhere
> >
> >
> >