RE: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]

Christian Huitema <huitema@microsoft.com> Sun, 22 September 2013 04:41 UTC

Return-Path: <huitema@microsoft.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD47211E80F1 for <ietf@ietfa.amsl.com>; Sat, 21 Sep 2013 21:41:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z7O0o55qb0Qm for <ietf@ietfa.amsl.com>; Sat, 21 Sep 2013 21:41:34 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2lp0203.outbound.protection.outlook.com [207.46.163.203]) by ietfa.amsl.com (Postfix) with ESMTP id 624C811E80E3 for <ietf@ietf.org>; Sat, 21 Sep 2013 21:41:33 -0700 (PDT)
Received: from BLUPR03CA036.namprd03.prod.outlook.com (10.141.30.29) by BLUPR03MB051.namprd03.prod.outlook.com (10.255.209.151) with Microsoft SMTP Server (TLS) id 15.0.775.9; Sun, 22 Sep 2013 04:41:32 +0000
Received: from BL2FFO11FD037.protection.gbl (2a01:111:f400:7c09::187) by BLUPR03CA036.outlook.office365.com (2a01:111:e400:879::29) with Microsoft SMTP Server (TLS) id 15.0.775.9 via Frontend Transport; Sun, 22 Sep 2013 04:41:32 +0000
Received: from mail.microsoft.com (131.107.125.37) by BL2FFO11FD037.mail.protection.outlook.com (10.173.161.133) with Microsoft SMTP Server (TLS) id 15.0.775.5 via Frontend Transport; Sun, 22 Sep 2013 04:41:31 +0000
Received: from TK5EX14MBXC272.redmond.corp.microsoft.com ([169.254.2.77]) by TK5EX14HUBC107.redmond.corp.microsoft.com ([157.54.80.67]) with mapi id 14.03.0136.001; Sun, 22 Sep 2013 04:40:48 +0000
From: Christian Huitema <huitema@microsoft.com>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, IETF discussion list <ietf@ietf.org>
Subject: RE: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]
Thread-Topic: [Fwd: I-D Action: draft-carpenter-prismatic-reflections-00.txt]
Thread-Index: AQHOtb2mKesZiaa+N0Ck1c4bnhAKpZnRLkFg
Date: Sun, 22 Sep 2013 04:40:47 +0000
Message-ID: <C91E67751B1EFF41B857DE2FE1F68ABA153DB96C@tk5ex14mbxc272.redmond.corp.microsoft.com>
References: <523BD51A.2080101@gmail.com>
In-Reply-To: <523BD51A.2080101@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.54.51.34]
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Forefront-Antispam-Report: CIP:131.107.125.37; CTRY:US; IPV:CAL; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(199002)(189002)(2473001)(6806004)(76786001)(83072001)(47976001)(50986001)(74876001)(74706001)(50466002)(44976005)(83322001)(74366001)(23746002)(81542001)(81342001)(54356001)(33656001)(69226001)(4396001)(49866001)(47736001)(81816001)(81686001)(65816001)(80976001)(59766001)(77982001)(56816003)(77096001)(76796001)(55846006)(53806001)(47446002)(74662001)(31966008)(74502001)(46102001)(80022001)(54316002)(56776001)(76482001)(47776003)(20776003)(63696002)(66066001)(51856001)(79102001); DIR:OUT; SFP:; SCL:1; SRVR:BLUPR03MB051; H:mail.microsoft.com; CLIP:131.107.125.37; FPR:; RD:InfoDomainNonexistent; A:1; MX:1; LANG:en;
X-O365ENT-EOP-Header: Message processed by - O365_ENT: Allow from ranges (Engineering ONLY)
X-Forefront-PRVS: 09778E995A
X-OriginatorOrg: DuplicateDomain-a84fc36a-4ed7-4e57-ab1c-3e967bcbad48.microsoft.com
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 22 Sep 2013 04:41:40 -0000

> I got my arm slightly twisted to produce the attached: a simple
> concatenation of some of the actionable suggestions made in the
> discussion of PRISM and Bruce Schneier's call for action.

Brian,

This is a useful summary, but I would like to see a few additions:

1) Encourage protocol designs that rely on peer-to-peer transmission, rather than intermediate relays, because relays are natural targets for interception services.

2) Encourage distributed services over centralized services. For example, social networking services today are heavily centralized. A distributed architecture would allow distribution of data at multiple location, managed by different commercial companies and covered by different legal authorities.

3) Require security sections of new RFC to include "mass surveillance" in their threat model and consider mitigations.

-- Christian Huitema