Re: Address privacy (was: Re: RFC4941bis: consequences of many addresses for the network)

Fernando Gont <fgont@si6networks.com> Tue, 28 January 2020 02:12 UTC

Return-Path: <fgont@si6networks.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D6423A0939 for <ipv6@ietfa.amsl.com>; Mon, 27 Jan 2020 18:12:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.307
X-Spam-Level:
X-Spam-Status: No, score=-0.307 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DATE_IN_PAST_03_06=1.592, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CSZmZp4jh4t0 for <ipv6@ietfa.amsl.com>; Mon, 27 Jan 2020 18:12:48 -0800 (PST)
Received: from fgont.go6lab.si (fgont.go6lab.si [91.239.96.14]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B3823A08FF for <ipv6@ietf.org>; Mon, 27 Jan 2020 18:12:48 -0800 (PST)
Received: from [192.168.100.103] (unknown [186.183.48.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by fgont.go6lab.si (Postfix) with ESMTPSA id 3C19E86B8E; Tue, 28 Jan 2020 02:36:23 +0100 (CET)
Subject: Re: Address privacy (was: Re: RFC4941bis: consequences of many addresses for the network)
To: "Manfredi (US), Albert E" <albert.e.manfredi@boeing.com>, Gyan Mishra <hayabusagsm@gmail.com>
Cc: 6man WG <ipv6@ietf.org>
References: <6f2a8e5a-a4f6-219b-d7c8-ba79ed257785@huitema.net> <233CE79D-B9BF-4335-8568-D178BD10CEAC@puck.nether.net> <CABNhwV2faDm=8t8KqNVJ5rWkU8or=0pyGmN8D8OyWj1S9ujVhg@mail.gmail.com> <CABNhwV2gY71PrjWQBUdtCU2Og_R3QawLNcANgVmov_3vJz4CvQ@mail.gmail.com> <31ec4e557f8846599f1161ccdf86348b@boeing.com>
From: Fernando Gont <fgont@si6networks.com>
Message-ID: <48fc8410-5abb-a58f-396a-a7af4b7d97c7@si6networks.com>
Date: Mon, 27 Jan 2020 19:25:03 -0300
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.1
MIME-Version: 1.0
In-Reply-To: <31ec4e557f8846599f1161ccdf86348b@boeing.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/X1T2dzOfdYzY6c1b-2fr-YcA4dI>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jan 2020 02:12:54 -0000

On 26/1/20 18:39, Manfredi (US), Albert E wrote:
> From: ipv6 <ipv6-bounces@ietf.org> On Behalf Of Gyan Mishra
> 
>> Microorganisms 2013 presentation
> http://download.microsoft.com/download/F/D/F/FDF4CF55-5FDE-4CFF-8539-3662BB5EB7A0/TD13Basel2-43.pptx
>>
>> So Microsoft, still being a major stakeholder In the desktop OS arena, as stated in the 2013 presentation above, has implemented RFC 4941 starting with Vista with the MD5 randomize generated IID that is stored and persistent across reboot and only changes if the prefix changes with mobility and a new 128 bit address stable address is generated.
> 
> This seems like a good default, no? The business about "privacy" concerns not so much the type of privacy that data encryption would provide, but rather, being able to track an individual in his/her travels. Changing the IID only when the prefix changes should prevent that well enough?

That's what RFC7217 does. RFC4941 is a mitigation about activity 
correlation in time (as opposed to "across network topology", which 
rfc7217 already mitigates).

-- 
Fernando Gont
SI6 Networks
e-mail: fgont@si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492