Re: Admission Control to the IETF 78 and IETF 79 Networks

Russ Housley <housley@vigilsec.com> Thu, 01 July 2010 19:20 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id EC53C3A6825 for <ietf@core3.amsl.com>; Thu, 1 Jul 2010 12:20:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.421
X-Spam-Level:
X-Spam-Status: No, score=-102.421 tagged_above=-999 required=5 tests=[AWL=0.178, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FSPzWxWvju7X for <ietf@core3.amsl.com>; Thu, 1 Jul 2010 12:20:20 -0700 (PDT)
Received: from odin.smetech.net (mail.smetech.net [208.254.26.82]) by core3.amsl.com (Postfix) with ESMTP id 0AC353A6784 for <ietf@ietf.org>; Thu, 1 Jul 2010 12:20:20 -0700 (PDT)
Received: from localhost (unknown [208.254.26.81]) by odin.smetech.net (Postfix) with ESMTP id 85F6D9A477D; Thu, 1 Jul 2010 15:21:08 -0400 (EDT)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([208.254.26.82]) by localhost (ronin.smetech.net [208.254.26.81]) (amavisd-new, port 10024) with ESMTP id aL8es63XP8Nu; Thu, 1 Jul 2010 15:20:25 -0400 (EDT)
Received: from [192.168.2.108] (pool-96-241-163-123.washdc.fios.verizon.net [96.241.163.123]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id C74549A473C; Thu, 1 Jul 2010 15:21:07 -0400 (EDT)
Message-ID: <4C2CEA82.8010904@vigilsec.com>
Date: Thu, 01 Jul 2010 15:20:34 -0400
From: Russ Housley <housley@vigilsec.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.10) Gecko/20100512 Thunderbird/3.0.5
MIME-Version: 1.0
To: Iljitsch van Beijnum <iljitsch@muada.com>
Subject: Re: Admission Control to the IETF 78 and IETF 79 Networks
References: <CFB08C07-DE90-47BE-ADFF-FC72162BBFA1@daedelus.com> <4C2BBD51.2060605@ietf.org> <6.2.5.6.2.20100701070804.0c26b8a0@resistor.net> <6D6E25E2-057B-4591-9288-1283036D0374@cisco.com> <20100701154421.GB43159@shinkuro.com> <92C447BB-792E-4EF7-ACAC-C91A4D27DC51@bogus.com> <20100701170744.GD43159@shinkuro.com> <4D37C04B-711B-4B1E-8299-3B0CD85D2DC4@muada.com>
In-Reply-To: <4D37C04B-711B-4B1E-8299-3B0CD85D2DC4@muada.com>
X-Enigmail-Version: 1.0.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Jul 2010 19:20:21 -0000

Iljitsch:

>> This is useful, but not quite what I was asking.  Clearly, the above
>> means that the logs exist during the meeting, while we are at the host
>> venue.  I think it is safe to say that under some legal regimes, a
>> government could require the delivery of such existing logs to them.
>
> I would very much appreciate assurances that such logging will not occur,
> and that there will be no "live" feed of such information to third
parties,
> such as government or law enforcement.
>
> A week's worth of correlation between my MAC address and the IP addresses
> that I exchange encrypted information with is not something I think any
> government needs to have.
>
> Of course if a government has cause to believe that a given user is
> misbehaving they still have the option to talk to the NOC staff and
> have them obtain information about this user.

As I said in my reply to Andrew, no matter where a meeting is held, we
are subject to the laws of that location.  Nothing new there.

We have received no requests for the kind of "live" feeds that you
suggest.  I'm quite sure that the NOC Team and the IAOC would push back
is such a request were made.

Again, the use of anonymous registration IDs is available to you and
anyone that wants one.  If you are concerned about the logs, then you
should use one.

Russ