Re: Proposed Statement on "HTTPS everywhere for the IETF"

"Roland Dobbins" <> Mon, 01 June 2015 22:41 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 7D0271A0687 for <>; Mon, 1 Jun 2015 15:41:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 9KL5SACsubhl for <>; Mon, 1 Jun 2015 15:41:23 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:400e:c03::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 4C8421A064C for <>; Mon, 1 Jun 2015 15:41:23 -0700 (PDT)
Received: by padjw17 with SMTP id jw17so46651887pad.2 for <>; Mon, 01 Jun 2015 15:41:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=uQrz0HFQUrXdYeFqT6d/+4KUVfbbqFTBJSId341GcMw=; b=fJcqEaKC4kI+OEsDnWDCJ9zpGVclUzSE5nK2LWcimjwA2cqCOOjQACW/emeoI3Vs7U +M8X/dJiZpu1krn8yTDK6WyRKxgORLa0w+9Dd75WGE09r3Da4FUu9hmaCnhe9dRoyIOz eqK+tLS3rZBD1tnfkky3j04SAj457vMCIIuEY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=uQrz0HFQUrXdYeFqT6d/+4KUVfbbqFTBJSId341GcMw=; b=UShPqeWibwv/7M2K45sXPQLWgjrMK2wY+iLZeIMvN/klvHFSykOzte0TmuU7lbeEkv q7eJjtsYPhe7sYt5jdGCbhwdaWpW7weQ998+3H+ncRUziB5oWDAmaCGJclK+gr11RV0W GgZ3RzIAhksK460Yppl6THTmN9b5Aoo8i+p8zLSSE3ogTNNqtKEhV2KGKqf2ZmCvtdwA 0sDExJO+QrxVLOoEnVsILM28iyYK/55v0cE+musVnrSyxDPPjthwX8TF5pPcT8P0mQgO jqPRroNQYzAFtnEN0YgmPvOKimlAnpLLVsc4nTw3rE/26deSaZdcsIIjyFiTH4SowHEO UCkw==
X-Gm-Message-State: ALoCoQlvaUoDrdVZfB2CnmxS6IEUpeSJo18s7ROX62vBmTIJcgtS66FNYoJAylQ9f2H6Ix1W6Eut
X-Received: by with SMTP id qb1mr6900886pbb.112.1433198483004; Mon, 01 Jun 2015 15:41:23 -0700 (PDT)
Received: from [] ( []) by with ESMTPSA id pw9sm15651942pac.27.2015. for <> (version=TLSv1 cipher=RC4-SHA bits=128/128); Mon, 01 Jun 2015 15:41:21 -0700 (PDT)
From: "Roland Dobbins" <>
Subject: Re: Proposed Statement on "HTTPS everywhere for the IETF"
Date: Tue, 02 Jun 2015 05:41:17 +0700
Message-ID: <>
In-Reply-To: <>
References: <> <> <1472054.O9DP0qoCQf@gongo> <>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.1r5084)
Archived-At: <>
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 01 Jun 2015 22:41:24 -0000

On 2 Jun 2015, at 4:27, Paul Wouters wrote:

> We had to cater to governments banning encryption for its users, and 
> we now see what that got them.

They just go around the encryption and compromise the endpoints.  
They're *governments*, so they have the resources to do that (not 
debating whether or not they should, just stating observed fact).

Also, universal or near-universal encryption is a serious problem in 
terms of detection, classification, traceback, and mitigation of 
application-layer DDoS attacks.  It drastically limits the scaling 
capacity of defenders, and results in even more cost asymmetry between 
defenders and attackers (in favor of the attackers).

My guess is that those who make bold, sweeping statements about how 
everything ought to be encrypted all the time are rarely those who have 
to deal with the unintended consequences of overencryption.

In the final analysis, there are no technical solutions for social ills. 
  The entire issue of unwanted surveillance by government entities is a 
social and political problem; it seems pretty clear that since the 
social/political side of things aren't proving to be easily resolved, 
that some folks are advocating doing *something*, *anything*, 
irrespective of whether it will actually make a positive impact on the 
conditions to which they object and without regard to the non-trivial 
side-effects of what they're advocating.

The IESG and the IETF in general should concentrate on technical issues, 
and work on solving social and political problems should take place in 
other, more appropriate appropriate fora, IMHO.

Roland Dobbins <>