Re: COVID-19 contacts tracker (Re: a brief pondering)

Keith Moore <moore@network-heretics.com> Wed, 15 April 2020 18:58 UTC

Return-Path: <moore@network-heretics.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CDC43A0791 for <ietf@ietfa.amsl.com>; Wed, 15 Apr 2020 11:58:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=messagingengine.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T1rfZzag5F6r for <ietf@ietfa.amsl.com>; Wed, 15 Apr 2020 11:58:22 -0700 (PDT)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA3863A07A9 for <ietf@ietf.org>; Wed, 15 Apr 2020 11:58:20 -0700 (PDT)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id 19207A42; Wed, 15 Apr 2020 14:58:20 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Wed, 15 Apr 2020 14:58:20 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=QhnD1c2ZC5UvgrxbjK+BZuAHS7bwd8sqwQGryxcFP 1s=; b=pjUUYGr4QZfvqR1whPmDixxaO7VepOXkrz0ds0TarvxnCIbZvmccV1f8t OBpresFUqGiAU/UPcft7G9SzT6Wvw4tJTag+Vde3rPtAgi6i6WzygYS1sAGdvCYX reC0PHQyy5G8PnQ/zChfZOmYDwiZ1AU6g/GIZQ5xrDPTziY7a7wSFpVk4YViaT0j y7dkZWcOH4NAprY34o2UliQUGT2xN0hfN/0QepxPIJ1H80kq+efVtWLirV5LKsY3 mV78YYe/H6kEXsL2OhV6J6GpHE0vNM3FTip9zGusv2By/fGEGLhVO604mHPb0dt7 S4ze8V1Hz57MdsbQ1fq728wSUAlMA==
X-ME-Sender: <xms:S1mXXtydgmmLD8ORl3U2H2ERrKJez6btU27W5OQlNj26rpRd_vJAQw>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduhedrfeefgdduvdduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefuvfhfhffkffgfgggjtgfgsehtke ertddtfeehnecuhfhrohhmpefmvghithhhucfoohhorhgvuceomhhoohhrvgesnhgvthif ohhrkhdqhhgvrhgvthhitghsrdgtohhmqeenucfkphepuddtkedrvddvuddrudektddrud ehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepmhho ohhrvgesnhgvthifohhrkhdqhhgvrhgvthhitghsrdgtohhm
X-ME-Proxy: <xmx:S1mXXmEbAaDDH1wnstF-jB2anKZlmlreR767AFD0zXFAmel3mgM6GQ> <xmx:S1mXXtoW5w1ls-dK4bLcwcRi-1sM2YJZ-naplKZTSLn6XOc4U2HI1A> <xmx:S1mXXmIMcZgBpJVNetDeT4LSWRvr95wfCP4svfft0MqWnJMS4C7KSw> <xmx:S1mXXgZwgi6au4T6f1jk5yQUwZdNwIPBcCZdLgkNAot6ptbMSLuLzw>
Received: from [192.168.1.97] (108-221-180-15.lightspeed.knvltn.sbcglobal.net [108.221.180.15]) by mail.messagingengine.com (Postfix) with ESMTPA id 487BA306005C; Wed, 15 Apr 2020 14:58:19 -0400 (EDT)
Subject: Re: COVID-19 contacts tracker (Re: a brief pondering)
To: ietf@ietf.org
References: <fd6b7ee2-cdbe-14a1-0087-ce61282b22f6@lear.ch> <29D0DCA7-1D72-428F-A6DD-05511D90C039@cable.comcast.com> <2fa6a8c8-7639-a378-2ff1-3f8697556b66@cisco.com> <24cd67ab-df5a-cc2f-745f-ace19d5325ea@network-heretics.com> <FD9C31D9-7113-40D7-8AB1-E581458DB02F@webweaving.org>
From: Keith Moore <moore@network-heretics.com>
Message-ID: <922752c9-7ac6-ff32-35c5-7035e49e22ff@network-heretics.com>
Date: Wed, 15 Apr 2020 14:58:18 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.1
MIME-Version: 1.0
In-Reply-To: <FD9C31D9-7113-40D7-8AB1-E581458DB02F@webweaving.org>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/rGPJPsvaJ8EZMyOlmMIv2hFZeW8>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Apr 2020 18:58:27 -0000

On 4/15/20 2:46 PM, Dirk-Willem van Gulik wrote:

> Now obviously - there is nothing stopping someone of using the very 
> same spec to accomplish something different; to spike the app, put 
> hidden code in it, etc, etc.  But that is something that we have any 
> way - those that control the phone in your pocket can put a spy in 
> your pocket.

Exactly.   And I believe the chance that this will not be misused, 
somewhere in the world, and probably many places, is zero.

If the net has taught us anything I think it's that anything that can be 
misused will be misused, especially to violate privacy. And the bad guys 
have time on their side.

To be clear, I don't think this is a problem that can be solved by 
protocol design.   Unless/until we can actually audit both the hardware 
and software in our mobile devices, we're vulnerable to whatever the big 
companies put in those devices, and to whatever governments demand of them.