Re: Call for Community Feedback: Retiring IETF FTP Service

ned+ietf@mauve.mrochek.com Tue, 17 November 2020 20:13 UTC

Return-Path: <ned+ietf@mauve.mrochek.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 351F73A03F2 for <ietf@ietfa.amsl.com>; Tue, 17 Nov 2020 12:13:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1bZaKZiot3Jf for <ietf@ietfa.amsl.com>; Tue, 17 Nov 2020 12:13:17 -0800 (PST)
Received: from mauve.mrochek.com (mauve.mrochek.com [98.153.82.211]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7FBDB3A0F0E for <ietf@ietf.org>; Tue, 17 Nov 2020 12:12:49 -0800 (PST)
Received: from dkim-sign.mauve.mrochek.com by mauve.mrochek.com (PMDF V6.1-1 #35243) id <01RS48O57HJK009GO7@mauve.mrochek.com> for ietf@ietf.org; Tue, 17 Nov 2020 12:07:46 -0800 (PST)
MIME-version: 1.0
Content-transfer-encoding: 7bit
Content-type: TEXT/PLAIN; CHARSET="US-ASCII"; format="flowed"
Received: from mauve.mrochek.com by mauve.mrochek.com (PMDF V6.1-1 #35243) id <01RS3WN35LXC005PTU@mauve.mrochek.com> (original mail from NED@mauve.mrochek.com) for ietf@ietf.org; Tue, 17 Nov 2020 12:07:41 -0800 (PST)
From: ned+ietf@mauve.mrochek.com
Cc: Adam Roach <adam@nostrum.com>, Keith Moore <moore@network-heretics.com>, ietf@ietf.org
Message-id: <01RS48O1GYLI005PTU@mauve.mrochek.com>
Date: Tue, 17 Nov 2020 12:04:07 -0800
Subject: Re: Call for Community Feedback: Retiring IETF FTP Service
In-reply-to: "Your message dated Tue, 17 Nov 2020 14:54:18 -0500" <83cc127d-e3ad-8a6f-1b7f-011dfddc0185@htt-consult.com>
References: <af6ab231024c478bbd28bbec0f9c69c9@cert.org> <0D41F3FD-BA1F-4716-A165-4FE7529431A9@vigilsec.com> <D26DCBB6-3997-4A73-BB46-867B4FD79BD2@eggert.org> <27b80ed2-76fb-aee7-f22d-de56019e9aa9@nostrum.com> <a8bdd67a-13ea-4433-aa38-9cfd48ea28da@network-heretics.com> <0e875497-9986-a0d9-8354-3eac26b7f882@nostrum.com> <a02e15f2-34fb-4124-7ba0-c0ee0070b39f@network-heretics.com> <6a29096e-c76e-9bde-388c-bf411b235346@nostrum.com> <6ff3c8a8-57c9-a278-51ce-ce24fd2dfc0e@network-heretics.com> <01RS3W7DNPHA005PTU@mauve.mrochek.com> <27622517-8EC3-44D1-BB21-1F2071BCA2C2@cable.comcast.com> <5dc7b0d1-d565-92c5-293e-093040596f35@network-heretics.com> <4b46fe4f-0b5b-dbf4-9bd5-f0a4a6ee30c9@nostrum.com> <83cc127d-e3ad-8a6f-1b7f-011dfddc0185@htt-consult.com>
To: Robert Moskowitz <rgm-ietf@htt-consult.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/ukph7OKT1I9N5AmKbwAobFhBct0>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Nov 2020 20:13:19 -0000


> On 11/17/20 10:57 AM, Adam Roach wrote:
> > On 11/17/20 09:45, Keith Moore wrote:
> >> Are those web browsers that are deprecating FTP also deprecating HTTP
> >> without TLS?
> >
> >
> > Yes.
> >
> > https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/
> >
> > https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure

> This causes grief with firewall authentication where plain http is
> needed for the firewall to intercept and force authentication.

The present situation with HSTS latching causes grief. The internal web
I used to use that was reliably http-only recently upgraded, forcing me
to find a different one.

HTTP support disappearing entirely, OTOH, is s disaster.

> How to shoot ourselves in the foot.

That's not your foot.

				Ned