Re: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]

Josh Howlett <Josh.Howlett@ja.net> Sun, 22 September 2013 21:39 UTC

Return-Path: <Josh.Howlett@ja.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB24711E814C for <ietf@ietfa.amsl.com>; Sun, 22 Sep 2013 14:39:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.525
X-Spam-Level:
X-Spam-Status: No, score=-100.525 tagged_above=-999 required=5 tests=[AWL=-0.340, BAYES_40=-0.185, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vyxLdoVq9VIn for <ietf@ietfa.amsl.com>; Sun, 22 Sep 2013 14:39:46 -0700 (PDT)
Received: from egw001.ukerna.ac.uk (egw001.ukerna.ac.uk [194.82.140.74]) by ietfa.amsl.com (Postfix) with ESMTP id EC48921F9929 for <ietf@ietf.org>; Sun, 22 Sep 2013 14:39:45 -0700 (PDT)
Received: from egw001.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id 9C3CF1AAFFC8_23F63A0B; Sun, 22 Sep 2013 21:39:44 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "staffmail.ja.net", Issuer "TERENA SSL CA" (verified OK)) by egw001.ukerna.ac.uk (Sophos Email Appliance) with ESMTPS id 5D5281AAFED9_23F63A0F; Sun, 22 Sep 2013 21:39:44 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.02.0247.003; Sun, 22 Sep 2013 22:39:43 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: Jari Arkko <jari.arkko@piuha.net>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Subject: Re: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]
Thread-Topic: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]
Thread-Index: AQHOtb2cIhmcJfhi2k6TjfZ901wwP5nOZI4AgAAIRICAAA0CAIAD0yuA
Date: Sun, 22 Sep 2013 21:39:43 +0000
Message-ID: <CE651C20.111D3%Josh.Howlett@Ja.net>
In-Reply-To: <96B39B2A-BBCC-4DF5-9189-78DEACC71512@piuha.net>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.3.6.130613
x-originating-ip: [194.82.140.76]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <0DCEABC7B0096047A58ACAE5D898B1FE@ukerna.ac.uk>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: IETF list <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 22 Sep 2013 21:39:59 -0000

Jari,

>It is important to understand the limitations of technology in this
>discussion. We can improve communications security, and in some cases
>reduce the amount information communicated. But we cannot help a
>situation where you are communicating with a party that you cannot
>entirely trust with technology alone. That does not mean we should not do
>anything.

Right. My primary concern was that the most effective responses for these
issues are rather different (technical controls versus regulatory
controls). I understand that "PRISM" is being used as a convenient label
to describe a multitude of sins; but, this will only be obvious to those
that understand the issues. Given the level of interest in this topic
(e.g., the daily media circus), we should be honest in what we can
practically achieve at a protocol level.

>I would also like to focus this topic on the general implications for
>Internet technology, rather than any specific alleged activities. The
>discussion has heightened our need to consider the large-scale monitoring
>threat. It is important to understand that the overall situation is
>probably bigger and more complex than we see today, and it will also
>evolve as time goes by. Hence: if we build something, lets build for the
>general case, reducing ability of outsiders to get into communications,
>reduce amount of sensitive information transported, make privacy attacks
>more costly, etc.

That's all good stuff. That said, personally I would characterise this as
a problem of Internet governance, and so I rather hope that ISOC have
ambitions beyond releasing a press statement.

Josh.



Janet(UK) is a trading name of Jisc Collections and Janet Limited, a 
not-for-profit company which is registered in England under No. 2881024 
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238