Re: draft-gont-6man-managing-privacy-extensions-00.txt

Fernando Gont <fernando@gont.com.ar> Sun, 13 March 2011 00:55 UTC

Return-Path: <fernando.gont.netbook.win@gmail.com>
X-Original-To: ipv6@core3.amsl.com
Delivered-To: ipv6@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4DA113A6AAA for <ipv6@core3.amsl.com>; Sat, 12 Mar 2011 16:55:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id exM5loB0UgkV for <ipv6@core3.amsl.com>; Sat, 12 Mar 2011 16:55:55 -0800 (PST)
Received: from mail-wy0-f172.google.com (mail-wy0-f172.google.com [74.125.82.172]) by core3.amsl.com (Postfix) with ESMTP id 610BB3A6A84 for <ipv6@ietf.org>; Sat, 12 Mar 2011 16:55:55 -0800 (PST)
Received: by wyb42 with SMTP id 42so3858660wyb.31 for <ipv6@ietf.org>; Sat, 12 Mar 2011 16:57:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:sender:message-id:date:from:user-agent :mime-version:to:cc:subject:references:in-reply-to :x-enigmail-version:openpgp:content-type:content-transfer-encoding; bh=E4gqvfl7ewZoumS5EuXq1TjV56jDgqgTj9lLXG2aln4=; b=o4WNG0L5XhhjLXIPARYVS1CtPPSVRDbaC7jqGsZVFaL1QbBvTzyVqnfyV2pFPoTyPm edGg099eewtGj3/RNwOuc//5Q1v5uV7rUlr63s2iC95VbmZ+2gmO0eaB3YqjjD64HnX7 09+Gd8uwGV6oTv0Lxxcx0LTM/CeU2t+wZ35mo=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=sender:message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:x-enigmail-version:openpgp:content-type :content-transfer-encoding; b=VRJWTAWg6D7Jb2jJ8KVP7QCqNOUkPC4Lsrw14RnARuzZOgNP3llHWwjuHWnQt6WFgf tvWyrht0CD+MGQ1nse5ulxjcznRIDAqJLvMDEP6Vu1OtHYJmg2IhnP2+T+v328PM88Ut NbGWwdICP/gyEfwk1CFrCwy5TWnUSiu3ln2Ag=
Received: by 10.216.87.8 with SMTP id x8mr9706724wee.46.1299977835923; Sat, 12 Mar 2011 16:57:15 -0800 (PST)
Received: from [192.168.200.18] ([194.2.150.133]) by mx.google.com with ESMTPS id l5sm3018247wej.32.2011.03.12.16.57.14 (version=TLSv1/SSLv3 cipher=OTHER); Sat, 12 Mar 2011 16:57:15 -0800 (PST)
Sender: Fernando Gont <fernando.gont.netbook.win@gmail.com>
Message-ID: <4D7C166A.9060608@gont.com.ar>
Date: Sat, 12 Mar 2011 21:57:14 -0300
From: Fernando Gont <fernando@gont.com.ar>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: Christian Huitema <huitema@microsoft.com>
Subject: Re: draft-gont-6man-managing-privacy-extensions-00.txt
References: <7111FC5F-BC3F-4242-9C3F-037E79894749@gmail.com> <alpine.DEB.1.10.1103091212570.7942@uplift.swm.pp.se> <4D77CBB9.1080702@gmail.com> <233b01cbdef5$8e214550$aa63cff0$@com> <25B3D469-F3DA-4A1D-A462-FEB71FA69485@gmail.com> <091D1284-99E4-450E-8AFF-7D4C6310D760@apple.com> <78B923726E7D59429936580CF127E943A13E758C27@eu1rdcrdc1wx032.exi.nxp.com> <262f01cbdf5d$607c69f0$21753dd0$@com> <4D7C0EE5.2080405@gont.com.ar> <22F6318E46E26B498ABC828879B08D4F0C2420@TK5EX14MBXW653.wingroup.windeploy.ntdev.microsoft.com>
In-Reply-To: <22F6318E46E26B498ABC828879B08D4F0C2420@TK5EX14MBXW653.wingroup.windeploy.ntdev.microsoft.com>
X-Enigmail-Version: 1.1.1
OpenPGP: id=D076FFF1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: "ipv6@ietf.org" <ipv6@ietf.org>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 13 Mar 2011 00:55:58 -0000

On 12/03/2011 09:44 p.m., Christian Huitema wrote:

>> It doesn't. The I-D aims at allowing routers specify which policy
>> they want hosts to employ when generating their IPv6 addresses.
> 
> Uh? I definitely don't want to give the router at Starbucks the means
> to specify the privacy configuration of my laptop.

Override the advice provided by the router at Starbucks, and you're done
(e.g., I guess this could even be automatically done by the OS depending
on how you tag the network you're connecting to (e.g., Public, Home,
whatever)).



> If we want policy options to be applied safely, they have to be
> propagated by trusted mechanism, where the host can verify the
> authority of the policy source. Anything else is abuse waiting to
> happen.

The threat model for this case is no different to that for ND in general...

Thanks,
-- 
Fernando Gont
e-mail: fernando@gont.com.ar || fgont@acm.org
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1