Re: Address privacy

Gyan Mishra <hayabusagsm@gmail.com> Mon, 27 January 2020 00:05 UTC

Return-Path: <hayabusagsm@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5AF6B1200DB for <ipv6@ietfa.amsl.com>; Sun, 26 Jan 2020 16:05:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Mq1bmV2FaLe2 for <ipv6@ietfa.amsl.com>; Sun, 26 Jan 2020 16:05:38 -0800 (PST)
Received: from mail-io1-xd2e.google.com (mail-io1-xd2e.google.com [IPv6:2607:f8b0:4864:20::d2e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1BFA12004A for <ipv6@ietf.org>; Sun, 26 Jan 2020 16:05:38 -0800 (PST)
Received: by mail-io1-xd2e.google.com with SMTP id d15so8091627iog.3 for <ipv6@ietf.org>; Sun, 26 Jan 2020 16:05:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=KBZdXxXHazMXI4B0LPC4weQPy5YxuJqZiJRmj+mgLsg=; b=a75Hf5W6/FxMGUtM7B61VwAB7hgyTXZr90T7eOozhEI3aJCFYefq0yUmSz03iJERsq SdQ9i0n2F6DMAqFyQeoS/tVenutUi0IHnM5l5umR8OWae7JdNDBIwOnuBekTrOKEVmv9 U8kKHy0klmFRlzz7M06O/JowaR7v5f69lDSxsbwHTlYNhNKpj1m7KWKTO1/wtX2UVmiE MAGiPlrcZla9yIPH4KfMg/W3bHXXPqAV1ZFKxbULst/kFZ5w3VDpBnQR18qvCXtDwohB Mqmm5l6kJXZwMTDbyBYJFvU4LH+lK3ylC3fkMDyi0xeBvBTOSgs8s2IjHrryWLRXRIiB hA0w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=KBZdXxXHazMXI4B0LPC4weQPy5YxuJqZiJRmj+mgLsg=; b=F6L3rOaXIQS9Np4H7MbtsP1baomoWM2sCGYn89IVOehIxQP8zEXTZboC4hEJjcAhT2 Z9K7JV1ovRS4KJRHmJOuOt3gqHYValyQXoHN+nHgTZzQHUe3HXqQ5J3cWxAO/J07cqv7 HGu/QN0fr1P/XahvoBK8auJ0tte0Jz7nCJJ9IHKpcsd45ALmwZdLgdBfheRvTYMYXG/W q1JHbLbiMbKI8vyPi1rhR9z2A7V8kTE3JxhPoBf3tLDRYvxYW0mVaj+OR5a3bLlcsYM7 NMBtLGfAz/uB5NH5TqSgCyEa4qjb4P66xmPiMJLHVCrjxhs1NYeQ27VxUwVuticcCCO6 JUPw==
X-Gm-Message-State: APjAAAWADANUlyd9+RqOSd/WtPdtH3ibPl2mU88y6bIVpkrWvzTjUZpZ N3EK86y9yNPqfhGNkHsqOgYZZ9JydhzUNAW7QF0=
X-Google-Smtp-Source: APXvYqy90+AY9Pb6Aj54ZbRGlCYKRNNamPpEASHUKg6+K9cuTyIXu+dNeUj2nQAvYIuam7r/SaQ8KR/yK2OdfWvUC5w=
X-Received: by 2002:a02:13c2:: with SMTP id 185mr11502910jaz.0.1580083537932; Sun, 26 Jan 2020 16:05:37 -0800 (PST)
MIME-Version: 1.0
References: <6f2a8e5a-a4f6-219b-d7c8-ba79ed257785@huitema.net> <233CE79D-B9BF-4335-8568-D178BD10CEAC@puck.nether.net> <CABNhwV2faDm=8t8KqNVJ5rWkU8or=0pyGmN8D8OyWj1S9ujVhg@mail.gmail.com> <CABNhwV2gY71PrjWQBUdtCU2Og_R3QawLNcANgVmov_3vJz4CvQ@mail.gmail.com> <31ec4e557f8846599f1161ccdf86348b@boeing.com> <18573398-e564-d7a4-d35c-fe72f117362b@gmail.com>
In-Reply-To: <18573398-e564-d7a4-d35c-fe72f117362b@gmail.com>
From: Gyan Mishra <hayabusagsm@gmail.com>
Date: Sun, 26 Jan 2020 19:05:27 -0500
Message-ID: <CABNhwV2AnPC++SzRSRwPWX_x8hU91cQAdgpvEKVAd8DbU--PcQ@mail.gmail.com>
Subject: Re: Address privacy
To: Brian E Carpenter <brian.e.carpenter@gmail.com>
Cc: 6man WG <ipv6@ietf.org>, "Manfredi (US), Albert E" <albert.e.manfredi@boeing.com>
Content-Type: multipart/alternative; boundary="000000000000fe7773059d13dd09"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/rJnX6HAqc3Hh18KFr4kx769VxUM>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Jan 2020 00:05:40 -0000

On Sun, Jan 26, 2020 at 5:00 PM Brian E Carpenter <
brian.e.carpenter@gmail.com> wrote:

> On 27-Jan-20 10:39, Manfredi (US), Albert E wrote:
> ....
> > This seems like a good default, no? The business about "privacy"
> concerns not so much the type of privacy that data encryption would
> provide, but rather, being able to track an individual in his/her travels.
> Changing the IID only when the prefix changes should prevent that well
> enough?
>
> The IID is normally set *before* the host generates its Link Local
> address, which is normally before it starts to listen for RAs from which it
> will learn the current prefix(es).
>
> So you'd have to make the IID for SLAAC independent of the IID for LL
> (which is of course exactly what RFC4941 does).


  Gyan>  Agreed.  So the happy medium achieved for two camps on opposite
ends of the spectrum.

1.  End user privacy on mobile device connected at home or

2.  End user privacy within an enterprise- non existent as IT security and
availability for mission critical applications -IPv6 stability and tracking
ability is the primary objective.

Happy medium achieved:
For both scenarios following RFC 4941 disabling the temporary address and
keeping the modified EUI-64 random IID - provides both privacy with MD5
randomized IID - and with the IID only changing with mobility when you
receive an new RA for SLAAC with mobility from a different subnet which is
what we want from and IT stability perspective.  If you reboot with
permanent storage as most devices have the IID does not change as long as
the prefix is the same.




>
>    Brian
>
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> --------------------------------------------------------------------
>
-- 

Gyan  Mishra

Network Engineering & Technology

Verizon

Silver Spring, MD 20904

Phone: 301 502-1347

Email: gyan.s.mishra@verizon.com