Re: https at ietf.org

jnc@mercury.lcs.mit.edu (Noel Chiappa) Thu, 07 November 2013 18:35 UTC

Return-Path: <jnc@mercury.lcs.mit.edu>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3022621E816A for <ietf@ietfa.amsl.com>; Thu, 7 Nov 2013 10:35:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.548
X-Spam-Level:
X-Spam-Status: No, score=-6.548 tagged_above=-999 required=5 tests=[AWL=0.051, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RpbkpWLByXIq for <ietf@ietfa.amsl.com>; Thu, 7 Nov 2013 10:35:04 -0800 (PST)
Received: from mercury.lcs.mit.edu (mercury.lcs.mit.edu [18.26.0.122]) by ietfa.amsl.com (Postfix) with ESMTP id CC84611E81B3 for <ietf@ietf.org>; Thu, 7 Nov 2013 10:35:00 -0800 (PST)
Received: by mercury.lcs.mit.edu (Postfix, from userid 11178) id 4698B18C0D6; Thu, 7 Nov 2013 13:35:00 -0500 (EST)
To: ietf@ietf.org
Subject: Re: https at ietf.org
Message-Id: <20131107183500.4698B18C0D6@mercury.lcs.mit.edu>
Date: Thu, 07 Nov 2013 13:35:00 -0500
From: jnc@mercury.lcs.mit.edu
Cc: jnc@mercury.lcs.mit.edu
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Nov 2013 18:35:08 -0000

    > From: Tim Bray <tbray@textuality.com>

    > Wikipedia is taking the position that it's nobody's business who's
    > reading about what .. For example, a gay teenager in Uganda can read
    > about potential health problems with greatly lessened fear of exposure
    > and torture.

Somehow I doubt that someone tapping their communication is the biggest of
their worries on that score. Having someone look at their screen over their
shoulder, or any one of a number of things like that, is realistically a
bigger danger.

Heck, having their computer infected with a virus that allows people to spy on
their activities on it is probably more likely to happen. Shall we get rid of
JaveScript and all other active Web content (the way most of these things get
in, these days) to help protect people's privacy?

Forcing everyone who uses Wikipedia (or the IETF web sites) to use HTTPS may
make people feel good, and/or serve as an expression of outrage at widespread
surveillance, but I'm not sure it's much more than that. (Sure, make HTTPS
available, but just be realistic about how much good it will do.)


    > From: Yoav Nir <ynir@checkpoint.com>

    > Your IT department might take a dim view of the kinds of articles that
    > you read

At many companies, the IT department can monitor _everything_ their employees
do on company-supplied equipment - and it's totally legal for them to do so.

    > the government agency might think you either a threat or a good target
    > for blackmail if they know the kind of articles that you read.

And don't even get me started on all the ways large, powerful governments have
of prying into people's lives...

	Noel