Re: 3484bis and privacy addresses

Doug Barton <dougb@dougbarton.us> Fri, 30 March 2012 00:00 UTC

Return-Path: <dougb@dougbarton.us>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0141221F8503 for <ipv6@ietfa.amsl.com>; Thu, 29 Mar 2012 17:00:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.627
X-Spam-Level:
X-Spam-Status: No, score=-3.627 tagged_above=-999 required=5 tests=[AWL=-0.028, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vpIabeC2qA44 for <ipv6@ietfa.amsl.com>; Thu, 29 Mar 2012 17:00:23 -0700 (PDT)
Received: from mail2.fluidhosting.com (mx22.fluidhosting.com [204.14.89.5]) by ietfa.amsl.com (Postfix) with ESMTP id 4182E21F8501 for <ipv6@ietf.org>; Thu, 29 Mar 2012 17:00:23 -0700 (PDT)
Received: (qmail 18611 invoked by uid 399); 30 Mar 2012 00:00:16 -0000
Received: from unknown (HELO ?172.17.198.146?) (dougb@dougbarton.us@12.207.105.210) by mail2.fluidhosting.com with ESMTPAM; 30 Mar 2012 00:00:16 -0000
X-Originating-IP: 12.207.105.210
X-Sender: dougb@dougbarton.us
Message-ID: <4F74F78F.1020002@dougbarton.us>
Date: Thu, 29 Mar 2012 17:00:15 -0700
From: Doug Barton <dougb@dougbarton.us>
Organization: http://SupersetSolutions.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20120327 Thunderbird/11.0.1
MIME-Version: 1.0
To: Alex Abrahams <alex@technicalenlightenment.com>
Subject: Re: 3484bis and privacy addresses
References: <4F716D5C.40402@innovationslab.net> <4F71F217.7000209@globis.net> <03d301cd0d97$b3361060$4001a8c0@gateway.2wire.net> <CAFnCNEdWUFDjoCBKeZYiCwEjvAepqK2ZXrsy+yoKmQze5vwKmQ@mail.gmail.com>
In-Reply-To: <CAFnCNEdWUFDjoCBKeZYiCwEjvAepqK2ZXrsy+yoKmQze5vwKmQ@mail.gmail.com>
X-Enigmail-Version: 1.4
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: ipv6@ietf.org
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Mar 2012 00:00:24 -0000

On 3/29/2012 6:13 AM, Alex Abrahams wrote:
> I'm sorry, but while I agree we have to think outside
> the corporate environment, I think we have to think way outside and we
> need to remember the kind of reasons why privacy exists, before saying
> the privacy extensions are only to keep a few hundred people happy.

I agree that the "few hundred people" thing was grating, and
unfortunate. But I think there is still a bit of a misunderstanding
about what problem 4941 (and its predecessor) was designed to address.

If you're in a corporate environment (at least in most of the western
world) you have ZERO expectation of privacy, and should act accordingly.
I anticipate that corporate IT departments who are concerned about the
problems presented by 4941 addresses are going to disable them as a
matter of policy. Period, end of discussion.

Also, if you're on a home network, it doesn't matter what the bottom 64
bits are, your network prefix is enough information for the bad guys to
use as ICBM targeting coordinates.

All that said, the real problem that 4941 was designed to fix was that
if you take the same system (think laptop, and now mobile phones,
iThing, etc.) and connect it to multiple different networks (as in, the
top 64 bits of your address are different) without 4941 or a similar
mechanism it is still possible to uniquely identify that host. For that
particular part of the problem, 4941 does very nicely, and end-user
devices don't (or shouldn't) care what address is being used for their
*outbound* connections, as long as their device and its applications
handle the situation correctly.

hth,

Doug