Re: Last Call: <draft-nottingham-safe-hint-05.txt> (The "safe" HTTP Preference) to Proposed Standard

Dave Crocker <dhc@dcrocker.net> Tue, 28 October 2014 00:53 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C2451A6FB9 for <ietf@ietfa.amsl.com>; Mon, 27 Oct 2014 17:53:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s57123ZvMrzc for <ietf@ietfa.amsl.com>; Mon, 27 Oct 2014 17:53:27 -0700 (PDT)
Received: from sbh17.songbird.com (sbh17.songbird.com [72.52.113.17]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6237C1A6EFF for <ietf@ietf.org>; Mon, 27 Oct 2014 17:53:27 -0700 (PDT)
Received: from [192.168.1.66] (76-218-8-156.lightspeed.sntcca.sbcglobal.net [76.218.8.156]) (authenticated bits=0) by sbh17.songbird.com (8.13.8/8.13.8) with ESMTP id s9S0rMO7011541 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Mon, 27 Oct 2014 17:53:26 -0700
Message-ID: <544EE8F9.3090506@dcrocker.net>
Date: Mon, 27 Oct 2014 17:53:13 -0700
From: Dave Crocker <dhc@dcrocker.net>
Organization: Brandenburg InternetWorking
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Brian E Carpenter <brian.e.carpenter@gmail.com>
Subject: Re: Last Call: <draft-nottingham-safe-hint-05.txt> (The "safe" HTTP Preference) to Proposed Standard
References: <20141027175757.50843.qmail@ary.lan> <544ECD1A.4010807@gmail.com> <D17FE653-87F8-41DE-B215-57AA907DF658@vpnc.org> <544ED90B.5020505@gmail.com>
In-Reply-To: <544ED90B.5020505@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.0 (sbh17.songbird.com [72.52.113.66]); Mon, 27 Oct 2014 17:53:26 -0700 (PDT)
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/MsobKbWboeE4TvMX6ETh_ByOtrI
Cc: IETF Discussion <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: dcrocker@bbiw.net
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Oct 2014 00:53:28 -0000

On 10/27/2014 4:45 PM, Brian E Carpenter wrote:
> No. I mean that a badly motivated web site can pretend to offer safe material
> using this but actually offer objectionable material (for whatever definition
> of safe or objectionable you care to adopt).


Brian,

That's a pretty surprising and quite disturbing criterion.  Apply it
consistently and we get no standards at all.  Ever.  Any site can choose
to be deceptive.

For example, when a message is relayed to a site and it accepts it, we
can't be sure it won't choose to mis-route it.

The purpose of the safe mechanism is to provide a standard way that a
user can state a basic desire to a server.  It is not the purpose of the
mechanism to guarantee that the server will behave honorably.

   1. The mechanism already has plenty of field experience demonstrating
basic utility.

   2. The proposed mechanism opts for simplicity.  More complexity would
actually increase the likelihood that a user's expectation's are not
matched.

Criticisms of the proposal are tending to miss the established
experience, or to propose entirely different designs that have no basis
from that experience, or to raise concerns that are frankly outside the
proper scope of the specification.

d/
-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net