Re: On the costs of old systems (was Re: Call for Community Feedback: Retiring IETF FTP Service)

Keith Moore <moore@network-heretics.com> Thu, 26 November 2020 21:06 UTC

Return-Path: <moore@network-heretics.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F6853A0FF1 for <ietf@ietfa.amsl.com>; Thu, 26 Nov 2020 13:06:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.918
X-Spam-Level:
X-Spam-Status: No, score=-1.918 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=messagingengine.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bC6OSaSAun28 for <ietf@ietfa.amsl.com>; Thu, 26 Nov 2020 13:06:48 -0800 (PST)
Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 34C523A0FF0 for <ietf@ietf.org>; Thu, 26 Nov 2020 13:06:48 -0800 (PST)
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.west.internal (Postfix) with ESMTP id 7A719109E for <ietf@ietf.org>; Thu, 26 Nov 2020 16:06:47 -0500 (EST)
Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Thu, 26 Nov 2020 16:06:47 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=4jgzLC trO2OSsZq9zYH5YXkmLlByQwEBouHlxHx2RBE=; b=BGwirVuNBBrXKuXpsRNR4k Do55gdwHMZwBJGNtNr8Mbont5FjlAOfGfH6e/3vt9wE1O9N6Tca8/hut/xWSccm4 OvC7KTrpBbLX5WTufo0uXsRix+JmV3BoZFF5adB31M/yToUrr98GVIea0KsqPUR2 XLK8EW4tKY++lzMc+7Mc9yls7+kMuP4ux4v+YcH1b2nCYZcWYZdhGwI9GjCj2wNs m3zfwX5C5BgjwE60+UVDKZcTvfVaUovMVNoVEhQ8y6C2i74fYlbXo6DcSjbVkim0 jFtnyg6vXAC59pT7CMOOFU7kV+qDIOTQKzBn/sW0UgJXHUx9xPMXubk7CI2UizGQ ==
X-ME-Sender: <xms:5RjAX5dHoNau59kRZf5o15cGeyqLeCvxeJFxZVkB5AV1gDLu2cEjPQ> <xme:5RjAX3NBupvqKI8aUBsydOfuLrvcEky74sDSSIyUB7ySiR9aO8h0SQYpeC1AIV2jH 5pIkxBnxbT-2Q>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedujedrudehvddgudegjecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecunecujfgurhepuffvfhfhkffffgggjggtsegrtd erredtfeejnecuhfhrohhmpefmvghithhhucfoohhorhgvuceomhhoohhrvgesnhgvthif ohhrkhdqhhgvrhgvthhitghsrdgtohhmqeenucggtffrrghtthgvrhhnpeevfeetudeige dtledvvddtudefjeejffdvfeetjeeiueelgfdtgfegtdffkeetudenucfkphepuddtkedr vddvuddrudektddrudehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrg hilhhfrhhomhepmhhoohhrvgesnhgvthifohhrkhdqhhgvrhgvthhitghsrdgtohhm
X-ME-Proxy: <xmx:5RjAXyiIf6xmqLQBNnrIGbMyC5Zk04XQl8UMMrfeoCOJ9Xyp_vru3A> <xmx:5RjAXy9VZIDzNg7mNxs-lhhos-WNWwAuF6QjokAvEp3_trOQzf6WSA> <xmx:5RjAX1tD2FRSS-Ck7fecQ3QsM1uxtI10vAay0l0FLN6A0P40Mr2AlQ> <xmx:5xjAX-PDhkqasO5EI2QCLY4NFqx6AB9ePGXxaa5IBRy785MUTPUTHQ>
Received: from [192.168.1.85] (108-221-180-15.lightspeed.knvltn.sbcglobal.net [108.221.180.15]) by mail.messagingengine.com (Postfix) with ESMTPA id 89E3A3064AB4 for <ietf@ietf.org>; Thu, 26 Nov 2020 16:06:45 -0500 (EST)
Subject: Re: On the costs of old systems (was Re: Call for Community Feedback: Retiring IETF FTP Service)
To: ietf@ietf.org
References: <af6ab231024c478bbd28bbec0f9c69c9@cert.org> <d12d2e09-6840-0500-c14c-73d862f85c8e@network-heretics.com> <20201117203038.GA30358@gsp.org> <4ddae8d0-866d-9e16-a304-ac78099f725d@cs.tcd.ie> <20201126195910.GA20255@gsp.org> <20201126201924.ilysbjg4bdwhpoak@crankycanuck.ca>
From: Keith Moore <moore@network-heretics.com>
Message-ID: <36e56480-bf69-6e15-2c5b-852f2c86c4b7@network-heretics.com>
Date: Thu, 26 Nov 2020 16:06:44 -0500
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0
MIME-Version: 1.0
In-Reply-To: <20201126201924.ilysbjg4bdwhpoak@crankycanuck.ca>
Content-Type: multipart/alternative; boundary="------------9AA52FF9699B39DDC64D9B42"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/wbGMgBlGfg491CMuwQhc5ysZIhw>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Nov 2020 21:06:50 -0000

On 11/26/20 3:19 PM, Andrew Sullivan wrote:

>
> I think this FTP discussion and the above share something, which is a 
> presumption that there are things that are just sitting around and 
> that don't require any attention.  I think this is false, and I would 
> like to suggest that just about everyone in this discussion knows that 
> to be the case, /but is forgetting it because the costs are 
> externalized/.

+1 to pretty much all of your message except for this last bit (italics 
mine).    Just because we don't mention the costs doesn't mean we're not 
aware of them.   (Though so far there's /still/ been no estimate of 
those costs, so basically we're left to guess.   And that might be part 
of why we don't say much about them.)

I do question the model that says that the security risks are related to 
the number of TCP ports used rather than, say, the number of lines of 
code that are exposed to externally originated traffic.   Of course 
that's not a great model either because the quality of the code matters, 
the implementation language matters, the protocol design matters, etc.

Keith