Re: [Model-t] Web Tracking

Töma Gavrichenkov <ximaera@gmail.com> Mon, 17 February 2020 19:19 UTC

Return-Path: <ximaera@gmail.com>
X-Original-To: model-t@ietfa.amsl.com
Delivered-To: model-t@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F37DE120864 for <model-t@ietfa.amsl.com>; Mon, 17 Feb 2020 11:19:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tw36Nwtp3990 for <model-t@ietfa.amsl.com>; Mon, 17 Feb 2020 11:19:02 -0800 (PST)
Received: from mail-yb1-xb30.google.com (mail-yb1-xb30.google.com [IPv6:2607:f8b0:4864:20::b30]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CD5A8120866 for <model-t@iab.org>; Mon, 17 Feb 2020 11:19:01 -0800 (PST)
Received: by mail-yb1-xb30.google.com with SMTP id f130so9201198ybc.7 for <model-t@iab.org>; Mon, 17 Feb 2020 11:19:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=Mb0KFlQDsFygT78gOBMITJHUw/sAUihW9lWpqA7jK8g=; b=lZrD/4hIKwDXQY9uNqR78vZVbvQuFyLmFEeICZoFnCqWcfHqTnJHk1lFebVwQxOd/l zPdPr6Vw3mJjyibhFKWl4h8gi3ed+PxKOGqt6WsoXcbNSdf9cpkb2zZgtMIs2nasNh3O 12oKNI9oV+RHXjR5v79D15I5k/iLh5My7iXpkKMgJVuzr9XmTGPUcyq6CDMfcFvu6Jr+ 8YhDFEpFDffoCPEMNSaU5bZDZtT6IOlWktFnxLEDLuLs1gI+zeOxW5jvPh0Wl9WZHWG0 g9AP7GMJEbG6dr5kdbSCOp/ICdVmaz/XNjsE1Y85lnMeLJrAYlJ9GjCc3GAnem7LTbJS Hdwg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=Mb0KFlQDsFygT78gOBMITJHUw/sAUihW9lWpqA7jK8g=; b=GwoAD8mlfWt2aOoLyna8pURMXb75j32Js8idKbgxev2ILaRKohtc1Vz5PHoH4yxzbz 7AL8WciUOOcG7+kTOcB9jQwA4mOQiN8Mb0RWHSigr8OlfUpJ7xnXWKI21bqBJktW9ur5 PUtYDgi2nJ4RVRhSF3btArf7DO4c5T2wum0U9greyp5rxZcnHwIz9X5pj3UOVf6YEF7J ede7zkvpOD2jhqLmZLgVhdTWLF4cLvliuEiNpG148fBjPVOI0oGC8nXEy9JyH3cpmvc3 BB5uo/DRhZwLinZoGre6hiSlLg7yxb37at0MdCiwdJj1sPgryt2XfaMtSe9LI6WFQ/0c Vhbw==
X-Gm-Message-State: APjAAAXdCo16yZV0MdQ/Huc/ZPgIEYshlJwpB5dEIxeaQkjvFGd5xGyP uSDmw9E7+Y+Js8FnG/teH/a1LUbUEgWIgKcR8nc=
X-Google-Smtp-Source: APXvYqzWYaRVV2rfZaC4iKqMEUOsy/uSH1+Vwo+C/q5Op6ncZYLWqUhy8lRU0435rSv7v3FSsYNhN7nGNP0KfdhOuN4=
X-Received: by 2002:a25:1544:: with SMTP id 65mr15033182ybv.107.1581967139072; Mon, 17 Feb 2020 11:18:59 -0800 (PST)
MIME-Version: 1.0
References: <CABcZeBN-HNe-j2japnCT5HR49__mxR7jiFAJ4NO27CdpuvirXw@mail.gmail.com>
In-Reply-To: <CABcZeBN-HNe-j2japnCT5HR49__mxR7jiFAJ4NO27CdpuvirXw@mail.gmail.com>
From: Töma Gavrichenkov <ximaera@gmail.com>
Date: Mon, 17 Feb 2020 22:18:43 +0300
Message-ID: <CALZ3u+b5LWSP4eu3DMWZ9om5rE2owehBHBTk1id=MJ9pvc-73Q@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Cc: model-t@iab.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/model-t/IRC-Jff-3XtMMh8q6V9uXdn5ZbE>
Subject: Re: [Model-t] Web Tracking
X-BeenThere: model-t@iab.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions of changes in Internet deployment patterns and their impact on the Internet threat model <model-t.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/model-t>, <mailto:model-t-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/model-t/>
List-Post: <mailto:model-t@iab.org>
List-Help: <mailto:model-t-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/model-t>, <mailto:model-t-request@iab.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Feb 2020 19:19:06 -0000

Peace,

On Mon, Feb 17, 2020 at 8:32 PM Eric Rescorla <ekr@rtfm.com> wrote:
> And here is our text on Web Tracking

The text doesn't mention a potential side channel issue.  E.g. today,
the world's largest user activity tracker is also the world's largest
Web browser vendor, so in theory, they technically (I'm not saying
"legally") don't need cookies at all.  Other side channels exist, e.g.
a DDoS protection provider who happens to also provide a VPN phone
app.

--
Töma