Re: Last Call: Adding a fragment identifier to the text/csv media type(see <draft-hausenblas-csv-fragment-06.txt>)

Pete Resnick <presnick@qti.qualcomm.com> Mon, 14 October 2013 19:45 UTC

Return-Path: <presnick@qti.qualcomm.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB29511E818E for <ietf@ietfa.amsl.com>; Mon, 14 Oct 2013 12:45:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.355
X-Spam-Level:
X-Spam-Status: No, score=-106.355 tagged_above=-999 required=5 tests=[AWL=-0.356, BAYES_00=-2.599, J_CHICKENPOX_43=0.6, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QKqQZbsFb734 for <ietf@ietfa.amsl.com>; Mon, 14 Oct 2013 12:45:35 -0700 (PDT)
Received: from wolverine02.qualcomm.com (wolverine02.qualcomm.com [199.106.114.251]) by ietfa.amsl.com (Postfix) with ESMTP id 6792521E80DC for <ietf@ietf.org>; Mon, 14 Oct 2013 12:45:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=qti.qualcomm.com; i=@qti.qualcomm.com; q=dns/txt; s=qcdkim; t=1381779934; x=1413315934; h=message-id:date:from:mime-version:to:cc:subject: references:in-reply-to:content-transfer-encoding; bh=t/NysL/l+KnzcMgBT7jS3hxmzyuI8ICR6jQsvh7yIjg=; b=NGe5XK5+GWoEYWwY7SmTRemC5g10Pa6DEMpWTeMC8QjJOLFKspSD+xVT cjVpB5IGIbvPP0pNDTrLdK0wqkd00fHpPZx+igqCWYznd/BoK2dKXuYBU oOVaT9zGn1bOtf99lTnfwjkooHo8Lqyb9P5yOHxCkGy6S+ycMk8BqDIXD Q=;
X-IronPort-AV: E=McAfee;i="5400,1158,7228"; a="81087780"
Received: from ironmsg03-r.qualcomm.com ([172.30.46.17]) by wolverine02.qualcomm.com with ESMTP; 14 Oct 2013 12:45:34 -0700
X-IronPort-AV: E=McAfee;i="5400,1158,7228"; a="568789881"
Received: from nasanexhc08.na.qualcomm.com ([172.30.39.7]) by Ironmsg03-R.qualcomm.com with ESMTP/TLS/RC4-SHA; 14 Oct 2013 12:45:33 -0700
Received: from resnick2.qualcomm.com (172.30.39.5) by qcmail1.qualcomm.com (172.30.39.7) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 14 Oct 2013 12:45:33 -0700
Message-ID: <525C49DC.9090102@qti.qualcomm.com>
Date: Mon, 14 Oct 2013 14:45:32 -0500
From: Pete Resnick <presnick@qti.qualcomm.com>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.7; en-US; rv:1.9.1.9) Gecko/20100630 Eudora/3.0.4
MIME-Version: 1.0
To: "t.p." <daedulus@btconnect.com>
Subject: Re: Last Call: Adding a fragment identifier to the text/csv media type(see <draft-hausenblas-csv-fragment-06.txt>)
References: <20131010185009.971.99426.idtracker@ietfa.amsl.com> <000f01cec801$0d8ba0a0$4001a8c0@gateway.2wire.net>
In-Reply-To: <000f01cec801$0d8ba0a0$4001a8c0@gateway.2wire.net>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [172.30.39.5]
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Oct 2013 19:45:39 -0000

On 10/13/13 5:42 AM, t.p. wrote:
> I find the security considerations in this registration rather weak.
> What might have sufficed in 2005 seems to me inadequate for 2013.  I
> would expect a clearer statement of what are or are not considered
> threats or attacks and what mitigations there then are for them.
>    

I don't know that everyone is really understanding the request that is 
being made here. It is a bit unusual.

RFC 4180 <http://tools.ietf.org/html/rfc4180> contains the current 
registration for text/csv. That registration has the "Change Controller" 
as "IESG", which is to say it's a registration from an IETF document. 
Barring any change, that registration would remain exactly as it is 
(including its current Security Considerations).

Someone outside of the IETF is publishing a document describing how to 
use fragment identifiers with text/csv. That document is being published 
in the Independent Stream by the RFC Editor. Since the publication of 
RFC 4180, "fragment identifier" was added to the media type registration 
procedures. <http://tools.ietf.org/html/rfc6838#section-4.11> The 
present document (draft-hausenblas) wants to update the existing IETF 
registration to include it's idea of fragment identifiers (which was 
absent from the RFC 4180 registration), though it will leave the IETF 
(via the IESG) as "Change Controller".

This Last Call is to find out if the IETF is OK with a non-IETF document 
updating an IETF registration. If the answer is "no", then we leave the 
4180 registration in place, or we tell the ISE that draft-hausenblas is 
not conforming to IETF processes and that we want it to be an 
IETF-stream document. If the answer is "yes", we go ahead with the 
registration change based on whatever the ISE publishes. We can send 
comments to the author and to the ISE asking for changes, but it's not 
an IETF document; IETF consensus is not required and the ISE can publish 
it anyway.

So, your Last Call comments are *simply* on the registration update. The 
document is not ours on which to comment.

pr

> ----- Original Message -----
> From: "The IESG"<iesg@ietf.org>
> To: "IETF Announcement List"<ietf-announce@ietf.org>
> Cc:<iana@iana.org>
> Sent: Thursday, October 10, 2013 7:50 PM
>
> The IESG has received a request to update the IANA registration of
> the text/csv media type, adding an optional fragment identifier.
> The request comes from a document in the Independent stream, and the
> IESG is the change controller for the text/csv media type.
>
> The IESG plans to make a decision in the next few weeks, and solicits
> final comments on this action. Please send substantive comments to the
> ietf@ietf.org mailing lists by 2013-10-24. Exceptionally, comments may
> be sent to iesg@ietf.org instead. In either case, please retain the
> beginning of the Subject line to allow automated sorting.
>
> The document making the request can be obtained via
> http://datatracker.ietf.org/doc/draft-hausenblas-csv-fragment/
>    

-- 
Pete Resnick<http://www.qualcomm.com/~presnick/>
Qualcomm Technologies, Inc. - +1 (858)651-4478