Re: Bounty: Consultation on DRAFT Infrastructure and Services Vulnerability Disclosure Statement

"Livingood, Jason" <Jason_Livingood@comcast.com> Thu, 06 August 2020 15:01 UTC

Return-Path: <Jason_Livingood@comcast.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3115A3A09C4 for <ietf@ietfa.amsl.com>; Thu, 6 Aug 2020 08:01:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=comcast.com header.b=dBCb82Gh; dkim=pass (2048-bit key) header.d=comcast.com header.b=qdhMTA2c; dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=comcastcorp.onmicrosoft.com header.b=bMXz02Mn
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tvLA9_eFdxM9 for <ietf@ietfa.amsl.com>; Thu, 6 Aug 2020 08:01:26 -0700 (PDT)
Received: from mx0b-00143702.pphosted.com (mx0b-00143702.pphosted.com [148.163.141.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D5EB63A0BF6 for <ietf@ietf.org>; Thu, 6 Aug 2020 08:01:10 -0700 (PDT)
Received: from pps.filterd (m0184890.ppops.net [127.0.0.1]) by mx0b-00143702.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 076EsHlG025154 for <ietf@ietf.org>; Thu, 6 Aug 2020 11:01:10 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcast.com; h=from : to : subject : date : message-id : content-type : content-id : content-transfer-encoding : mime-version; s=20190412; bh=BjO/5jhFU6UG3BYEJ/26FIhrVxDGh1Bs8gNwVtDm2gw=; b=dBCb82GhSXPJkSHe5pDlvEwMK1G1Hf0gPJNj5rfQ1FoW9ebUFFaHvym5+wt6EfOvegYM 1nXkLoProbH1OkgXPEYU6cjCoNs5QjXViB9pbfxekvEypFVdfSfkcA8GPuYZE6VZugdB LH8LAUSKb0UYABYehBxXfrbQSGytWE3wnX3RTAoYAPKxqaFMdErMn12FMIE1uvOcmG1q 3dPZ/O0U+ngcrmTmViyJkNn6UJC0gd1Q4mTpk5aSidUC2rDckkOrifjhvkSxXjiQ5dyu vygJzXcI0OS54BUunbp04UxckZtXKkv8u/TXseHfe0jEhXY3t4YSygeD83EdVDMIK7hc Kw==
Received: from pacdcmhout01.cable.comcast.com (PACDCMHOUT01.cable.comcast.com [68.87.31.167]) by mx0b-00143702.pphosted.com with ESMTP id 32rk8n8dvk-101 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <ietf@ietf.org>; Thu, 06 Aug 2020 11:01:09 -0400
DKIM-Signature: v=1; a=rsa-sha256; d=comcast.com; s=20190412; c=relaxed/simple; q=dns/txt; i=@comcast.com; t=1596726067; x=2460639667; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=BjO/5jhFU6UG3BYEJ/26FIhrVxDGh1Bs8gNwVtDm2gw=; b=qdhMTA2cERJhB9+z0YoCIhSZIQz3Xfg2lcY51r2hMunK/uCCOL1N0VTTTesFMN4C VaSJNyH+ToJnDaJoi3P99+1qa8QFmNIAkw8N1sejrtxGWLeWEx4at+B+NfHqixpr Ka4aLekkTs291mEju9EZ1KMCnV7nTIM5c26dKq5JKw7TF+1XFxaShp+QsOONuPiS zd+IZC74asDt2jJQI4ksYmlTDSCayv1frZv1ZsZQ0xO4hWjIeCnYCAyYHPSSRq/M iE85AkOANy/XjU0mUfE2pnTWEZ3mkCnnw4NLPNtWyk9GXyzu7jm736k9pjXJCAMm SP86SafJ5ugXjpciEc/KEA==;
X-AuditID: 44571fa7-417ff70000018e96-b4-5f2c1b3200d7
Received: from PACDCEX41.cable.comcast.com (cas-umc02.ndceast.pa.bo.comcast.net [68.87.34.28]) (using TLS with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (Client did not present a certificate) by pacdcmhout01.cable.comcast.com (SMTP Gateway) with SMTP id 2D.85.36502.23B1C2F5; Thu, 6 Aug 2020 11:01:06 -0400 (EDT)
Received: from PACDCEX48.cable.comcast.com (24.40.2.147) by PACDCEX41.cable.comcast.com (24.40.2.140) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 6 Aug 2020 11:01:06 -0400
Received: from PACDCEXEDGE01.cable.comcast.com (76.96.78.71) by PACDCEX48.cable.comcast.com (24.40.2.147) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Thu, 6 Aug 2020 11:01:06 -0400
Received: from NAM12-BN8-obe.outbound.protection.outlook.com (104.47.55.169) by webmail.comcast.com (76.96.78.71) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 6 Aug 2020 11:00:58 -0400
Received: from MN2PR11MB4287.namprd11.prod.outlook.com (2603:10b6:208:189::17) by BL0PR11MB3235.namprd11.prod.outlook.com (2603:10b6:208:6b::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3261.15; Thu, 6 Aug 2020 15:00:57 +0000
Received: from MN2PR11MB4287.namprd11.prod.outlook.com ([fe80::a8bd:6861:d1e5:e613]) by MN2PR11MB4287.namprd11.prod.outlook.com ([fe80::a8bd:6861:d1e5:e613%3]) with mapi id 15.20.3261.019; Thu, 6 Aug 2020 15:00:57 +0000
From: "Livingood, Jason" <Jason_Livingood@comcast.com>
To: "ietf@ietf.org" <ietf@ietf.org>
Subject: Re: Bounty: Consultation on DRAFT Infrastructure and Services Vulnerability Disclosure Statement
Thread-Topic: Bounty: Consultation on DRAFT Infrastructure and Services Vulnerability Disclosure Statement
Thread-Index: AQHWbAJjNrTOc3S+5k6Up6Y2g3tuBQ==
Date: Thu, 06 Aug 2020 15:00:57 +0000
Message-ID: <B8EC2B88-81B7-47F4-A9DF-34A49077857E@cable.comcast.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.39.20071300
authentication-results: ietf.org; dkim=none (message not signed) header.d=none; ietf.org; dmarc=none action=none header.from=cable.comcast.com;
x-originating-ip: [2601:87:4280:7190:7182:7d98:df48:c3ed]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 72d60704-6dea-4a1f-c526-08d83a19861d
x-ms-traffictypediagnostic: BL0PR11MB3235:
x-microsoft-antispam-prvs: <BL0PR11MB3235F6842F397BCF6CD6B126C7480@BL0PR11MB3235.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:4941;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: MYNkd8qXrbPPGs3Mbg/nPxGuxgTKhimfgmz6zjph0Rgxl7+9jaknwb/eefL+cobi3/ws+J7WCu4jTLfv+XwjSs/DKb8dJghZH79Vx2bvX7+xZ0fuCs7hiBrCifhsGth+u+wH65rlSbuAVCS0txVTcOjOLKIGEwha5gpZV8D9kOZdxTbTXOEdQSeJkXXLK9udxqveoRaZ3/UKfHNqQp5eVbVpF5XY7lhr1zMdXWimC4cy/C6fPAqRCvmeeL8pbAHby5U0txS4gTNuJrFvCUbcCxtl3yYdtugeogrCRl8/tdJcqaRcJ2WxSfFiQe1VOxBxy1o9WX7Q6a5kVarGbbGA1g==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4287.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(396003)(366004)(376002)(136003)(346002)(39860400002)(558084003)(186003)(2616005)(2906002)(6512007)(33656002)(6916009)(66446008)(71200400001)(5660300002)(316002)(76116006)(66946007)(6486002)(478600001)(8936002)(6506007)(86362001)(8676002)(64756008)(66476007)(66556008); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: UZKwYNevSujaXAQUdU0xg3HCd8H0rjTKFJt4FGSv2qMJgnhNJbcBhWXbSBvu4u4g6GRtKFEMEHnLxtnf+HAGyLFZFqBbqrnJ45CiN80nrm9Xa2QklkPFBn+2Nvin62yPAW2o+6l1NLjFwor4eLrDNW9O7hMnfU87cOzRadK/FpVQ/f35YEgZuXfrMWwaLy/+MjMKAHbGstNACf73g8SfmeWt3MgRe5Y+aw/QLvp+9eNI1HuJZew/13mf/0zX3/5rmfqN+KDcccLe+X6WfyS6vIyPMYY1htWyToQZ2ZVpM+/hoIF9PXH3lEPWdI/KWAh+lcfHaSqjwtcy7EcgxQFWu+HrPo4KEfzYJ/43GqosPEHhjzLVXq9xCiiyr69sRnNT7e4o6cRBie9o65CHRDhCh1cYrKBeOulnmVP5NrD7uBmx40WPBGzMapgqBnZBwIB6efc4zzFPsY1t6rVciWNnmwAN3ggGAbfdOAJ/APyne7NsWZv4VqIrvew+9xnMhP5qiSn3FZ+L3MpWWpXKbFDSl0RWOk/k8avHjUVAIqgoKO54NY5HBqmDc4pWbAvn+LcACITqsPolDXIAjBNjZ+Ly5uMXO4wxcagq/P9IHULoXnxwL+ZJis6wIPLubNgq6YG4glK8is2y7gHDT6PGyNEg4YDx7vKwCGSC9CGvpUT/8T6ErDn0AMfaiWdKJbqKxCbZnAFoYjHCoyVbmWK5m1WKbQ==
x-ms-exchange-transport-forked: True
arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VdRbBjgZTup6bDrco6j66U5Th3oDQ9e63T279lUdoqhr3jXBFdu+AZKBafAK7xq9Jte9z9NDuC3u29a3O7oG2FEG4aZwHHXoha2BjnDN9kVTMKAfb8RLDA4pIPGMzDtPfH0kdQDJQxPphJK3RK/REmqHROapbiSuQuqJuSmfrXB3OcGt11zkmWb99Z1SnS+FtAEzl4SwloktY1nJ2I8ArBPaOLY1ltaZ1jBRAaE8ZlgVXODJflyl1cdZNAj7DkxA+4SeST5TSM+DLTAow6enWm6j+Z179on4QOwlkGcxIkW74XoLrWqXsFVfgo8s9RydRCb8EvfuAGkiv8QEMp2Jzg==
arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=S06KsP6f3IgLzNX8KyBh0JFN/iyt2NwyeyV+ivi32ag=; b=TBW7D+6zaG5RTKcs9mWqUkyXqIO3znMBMCYC280h6TWGYTxTdRF8ZH8IRyLnzAt0K4OjrX1fQNKiaBh9Q7U9fitpkT8Q7wmP8/7wUBpfTzd58CjMauLwtpCPTdqo1oH5TamY+9PWK15Wk4izCtmE3zk4/yr4wgd6xvd2UxaXS6yoKR67tj5OdFgNWBxI6iLN0oG9Exr8JajtAawEViV/leBMxWoji8D3kO9buVPEn1uhdjKNPb3Jm3hfaXIYU6/8F8e3LJigK2wgmFw090bUkWIMJTscaVeGTvLEfStKzcLMtvZyG5dSlgMxAXJoRpH92XkKzlzNWoph4uGreUJn3g==
arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cable.comcast.com; dmarc=pass action=none header.from=cable.comcast.com; dkim=pass header.d=cable.comcast.com; arc=none
dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcastcorp.onmicrosoft.com; s=selector1-comcastcorp-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=S06KsP6f3IgLzNX8KyBh0JFN/iyt2NwyeyV+ivi32ag=; b=bMXz02Mnk9DXsuxmex9gE3N+h6YhM7es0xBL+Eg2RWEQsVPAjPcD3aFpgttXbsO5tOd3Jnrj8vngg7b/AehrYkQx8icBJiytGQ7Kdo5OsgPjaADlnisVYDvHmcq3XyWY1U/KlYGuTSBt/nUf0Hp1UavDgUBxiq/+WKKfLmIdqtg=
x-ms-exchange-crosstenant-authas: Internal
x-ms-exchange-crosstenant-authsource: MN2PR11MB4287.namprd11.prod.outlook.com
x-ms-exchange-crosstenant-network-message-id: 72d60704-6dea-4a1f-c526-08d83a19861d
x-ms-exchange-crosstenant-originalarrivaltime: 06 Aug 2020 15:00:57.0327 (UTC)
x-ms-exchange-crosstenant-fromentityheader: Hosted
x-ms-exchange-crosstenant-id: 906aefe9-76a7-4f65-b82d-5ec20775d5aa
x-ms-exchange-crosstenant-mailboxtype: HOSTED
x-ms-exchange-crosstenant-userprincipalname: 9bvw9l5h11+4h01eOfh63UHc9IyVLoMxCa+pxH7AwBooRDC8NNty70STAe04Umg+lBt0BbxERrTXLjeCZQ6IXsmJPDxl0AnCtccyq+wbtlc=
x-ms-exchange-transport-crosstenantheadersstamped: BL0PR11MB3235
x-originatororg: cable.comcast.com
Content-Type: text/plain; charset="utf-8"
Content-ID: <A550E8F6070A9D459564BBEB93C53F16@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Forward
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrLIsWRmVeSWpSXmKPExsXiEq4ko2ssrRNvcH0Dj8WzjfNZHBg9liz5 yRTAGMVlk5Kak1mWWqRvl8CV8fTkM7aCV4wVjWu2MzYwPmHsYuTkkBAwkVjac5e9i5GLQ0jg CJPEqcPvoZydjBLfWo+zQDhXGCU2PpoIlTnKKHFtw3ZmkH4hgcVMEr/+CEIkHjJKLFv/kgkk wSZgJnF34RWwIhEBZYkDM2+wgtjCAtkSV56dYYOI50jMm76KHcLWk+jY1AbWyyKgIrHn3j2w Gl4BF4mzczeygNiMAmIS30+tAathFhCXuPVkPhPEEwISS/acZ4awRSVePv4HtktUQF/idcdO JpDjGAUmMEr0t3wAKuIAKrKUWDhFDaJeVuLS/G5oYPhKNExbxwZha0ns3XgBan62xPUbU6Hm q0ksXbkBqkZOYlXvQxYIW0biwY3tbCC7JAR+M0m8fvCBHcI5wizxaNNKqEl/WCVWzJeHOEJF 4t+hygmMxrOQ/DMLKMMsoCmxfpc+RNhDYuPhK8wQtqLElO6H7LPAwSIocXLmE5YFjKyrGHnM LPQszPWMDfUMzcw3MYIThfzyHYzbZ2UcYhTgYFTi4U0R1YkXYk0sK67MPcQowcGsJMKb9UI7 Xog3JbGyKrUoP76oNCe1+BCjNAeLkjjvhKsv4oQE0hNLUrNTUwtSi2CyTBycUg2MazQ3XI86 GOvipafuuS3wr9GW2Ieys2fkbvB19pgRqb7B5VyzFfuhL3KH2h5/FHL2jXlwVfnbG49D+at3 z2URSWk6cNnPy5d3/blnKXafFojL3Il3+3mriT3d4KbXb/57p3+37312u8P7p9r/JXkP/uzT uWxhHVJ95LXy6++B1fqfJ+Td7P+3WYmlOCPRUIu5qDgRAOwLi1wQAwAA
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.235, 18.0.687 definitions=2020-08-06_12:2020-08-06, 2020-08-06 signatures=0
X-Proofpoint-Spam-Reason: safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/DvSLCd_4ljaKmWS3v5EFFZcUOF8>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Aug 2020 15:01:29 -0000

It would be great to see comment on this very important question:

>    * Whether or not this statement should be supplemented with a "bug bounty" program.

Jason