Re: [Model-t] w3c also thinking about threat models

Bret Jordan <jordan.ietf@gmail.com> Mon, 23 September 2019 15:18 UTC

Return-Path: <jordan.ietf@gmail.com>
X-Original-To: model-t@ietfa.amsl.com
Delivered-To: model-t@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 564F6120018 for <model-t@ietfa.amsl.com>; Mon, 23 Sep 2019 08:18:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8WyKNxa_oA4b for <model-t@ietfa.amsl.com>; Mon, 23 Sep 2019 08:18:23 -0700 (PDT)
Received: from mail-pl1-x632.google.com (mail-pl1-x632.google.com [IPv6:2607:f8b0:4864:20::632]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A47E3120013 for <model-t@iab.org>; Mon, 23 Sep 2019 08:18:23 -0700 (PDT)
Received: by mail-pl1-x632.google.com with SMTP id d22so6638097pll.7 for <model-t@iab.org>; Mon, 23 Sep 2019 08:18:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:mime-version:subject:date:references:to:in-reply-to:message-id; bh=0liszwVwdXFZYWcwndqHVR+TxmfehvaN9LaF/7WmLow=; b=WMQtjtUwOifEbQHSTLOae4YY8TeshjrhLVWXQZNlGI8zew24N9/qfWZdN5srzg6XDg EggbqmN5q81eTon2AkMKe9pTuuu5GkIaxQobB6lTxTImDgZzTclhSmdW7tDEYyHbLycb 19KU/SrcX/Q65ybWCdHYl/QjKxJfv/wI46CV2tLe4qxbav64NG532Ztf7+iqjdyqELyf +WCn4xYDKBuezaukzi3hEnzKWSxqjRUOBZoH8Joqv/1dbveoefokI5VrW2YkGNY+s4oU Vv7kE0HeOMjqCgrX+AY02pAwl6XNogxssADErqpvljzmglLz3VfPvcEzHoF5uqdSVqIz 7TMA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:date:references:to :in-reply-to:message-id; bh=0liszwVwdXFZYWcwndqHVR+TxmfehvaN9LaF/7WmLow=; b=fHkW3fvCpxo51yrWcbehbB2bTMuWEM6hGHo+J3tEO1ShoOYfPMEqLNSvfJxrLk29ew cBq2V2B33GOTUcROjE+HUu1ZWcAR8dqkXu/HPQfmzGiS6ZZfb0t1oEanBOAIpDuaxjOv e2uiawISOauk2PFW4a2T0o3eC1ghb36sf6396qwi+DCMR+K+3FWBVS9SdK/p7p/OO9Fk b1BzXoF7neyFvToayAFhS/F2sCQQbWWFmvKTp6rGfF6jrOr92xdL0gEW/TJGtqdFCfdz vGY7wS60PNu5Qk5g9wKdFIOLIIWdWUbmVyQKs8DFbsTURfn3pbwa7o5QRsJcU5CSBDD0 G1gw==
X-Gm-Message-State: APjAAAV3l9dZ816Ug3Wv0k0VnKYaMQM4Z6Rd0ctDJr43pgILnjYwDQpj wpwGOgmZtxOniFYQR2TXQA8=
X-Google-Smtp-Source: APXvYqyfxYNE4PKtvFiN7J7iEQ9OZMzlrBHDxk3AA5TBQ6mPcMlXGwcdAFIqnhZeg0wrliHNv7lXDg==
X-Received: by 2002:a17:902:524:: with SMTP id 33mr262407plf.123.1569251903148; Mon, 23 Sep 2019 08:18:23 -0700 (PDT)
Received: from [10.128.64.149] ([136.60.227.81]) by smtp.gmail.com with ESMTPSA id w65sm12732687pfb.106.2019.09.23.08.18.21 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 23 Sep 2019 08:18:22 -0700 (PDT)
From: Bret Jordan <jordan.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_A3B6ACD0-578D-4E5F-A1AC-35E76470E48D"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Mon, 23 Sep 2019 09:18:20 -0600
References: <a327c668-6a17-bb9f-318e-e3cea6c6c1d0@cs.tcd.ie> <624F4CA6-8D84-4BD8-A74C-E5AE22709F72@lastpresslabel.com> <A30308F8-D2A5-45CF-88D9-D65240972D51@gmail.com> <27c70832-a631-4622-6119-3a47928c634e@cs.tcd.ie> <49EC2254-981B-4B79-9116-AC24385C2287@gmail.com> <CACsn0cnT9nNKzAb7bewuSUPE=u=rocDpzbkOgrqXAZ+iGf+TUw@mail.gmail.com>
To: Watson Ladd <watsonbladd@gmail.com>, model-t@iab.org
In-Reply-To: <CACsn0cnT9nNKzAb7bewuSUPE=u=rocDpzbkOgrqXAZ+iGf+TUw@mail.gmail.com>
Message-Id: <4933108A-356D-4A9A-B00B-2EFFBF2689F0@gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/model-t/MjVkPy4VrL4SW4MrLsH0z-1aX0w>
Subject: Re: [Model-t] w3c also thinking about threat models
X-BeenThere: model-t@iab.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions of changes in Internet deployment patterns and their impact on the Internet threat model <model-t.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/model-t>, <mailto:model-t-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/model-t/>
List-Post: <mailto:model-t@iab.org>
List-Help: <mailto:model-t-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/model-t>, <mailto:model-t-request@iab.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Sep 2019 15:18:27 -0000

There are a lot more problem than an "RCE vulnerability due to memory safety issues". This response, IMO, is part of the problem.  We keep trying to tie things to a single thing.  The attack surface and security model is much much broader. 


Thanks,
Bret
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."

> On Sep 23, 2019, at 8:51 AM, Watson Ladd <watsonbladd@gmail.com> wrote:
> 
> 
> 
> On Mon, Sep 23, 2019, 7:41 AM Bret Jordan <jordan.ietf@gmail.com <mailto:jordan.ietf@gmail.com>> wrote:
> > the web has a reasonably worked out security model 
> 
> 
> Given how nearly all attacks, campaigns, malware, and intrusion sets use the web or software connecting to the web to either compromise victims, exfiltrate personal or private information from victims, or destroy victims’ information I think one could easily argue that your statement that there is "a reasonably worked out security model" is false. 
> 
> An RCE vulnerability due to memory safety issues isn't a a result of not thinking about the security model.
> 
> 
> 
> 
> Thanks,
> Bret
> PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
> "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
> 
>> On Sep 20, 2019, at 2:01 PM, Stephen Farrell <stephen.farrell@cs.tcd.ie <mailto:stephen.farrell@cs.tcd.ie>> wrote:
>> 
>> On 20/09/2019 18:48, Bret Jordan wrote:
>>> Yes, privacy is just one facet. 
>> 
>> Sure, it's clearly true that privacy is not everything
>> in the IETF context, nor in w3c either. I guess the
>> argument for putting more focus on privacy in w3c might
>> be that the web has a reasonably worked out, (even if
>> imperfect) security model (the SOP etc), but that the
>> web has been pretty awful for privacy. Well, that's an
>> argument I'd make, not sure if the people involved in
>> the w3c work would:-)
>> 
>> S.
>> 
>>> 
>>> 
>>> Thanks,
>>> Bret
>>> PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
>>> "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
>>> 
>>>> On Sep 20, 2019, at 11:12 AM, Dominique Lazanski <dml@lastpresslabel.com <mailto:dml@lastpresslabel.com>> wrote:
>>>> 
>>>> 
>>>> 
>>>>> On 20 Sep 2019, at 11:26, Stephen Farrell <stephen.farrell@cs.tcd.ie <mailto:stephen.farrell@cs.tcd.ie>> wrote:
>>>>> 
>>>>> 
>>>>> Hiya,
>>>>> 
>>>>> Hope we all had a nice summer break from this
>>>>> discussion, but I'd like to try see if we can
>>>>> get back at it, so I've added reviewing the
>>>>> various drafts folks have posted to my todo
>>>>> list - I hope to send some comments/reviews
>>>>> in the next week-ish.
>>>>> 
>>>>> In the meantime, it looks like w3c are also
>>>>> thinking about threat models [1] which is
>>>>> interesting.
>>>>> 
>>>>> Cheers,
>>>>> S.
>>>> 
>>>> Thanks for kick starting this list again especially after the summer!
>>>> 
>>>> Interesting W3C work, but I would add that they are only looking at privacy threat models so they have that covered. Perhaps we should look at system security threat models since W3C has kicked off their work specifically on privacy. That way we can be more holistic about the work.
>>>> 
>>>> Looking forward to the discussions.
>>>> 
>>>> Dominique
>>>> 
>>>> -- 
>>>> Model-t mailing list
>>>> Model-t@iab.org <mailto:Model-t@iab.org>
>>>> https://www.iab.org/mailman/listinfo/model-t <https://www.iab.org/mailman/listinfo/model-t>
>>> 
>>> 
>>> 
>> <0x5AB2FAF17B172BEA.asc>
> 
> -- 
> Model-t mailing list
> Model-t@iab.org <mailto:Model-t@iab.org>
> https://www.iab.org/mailman/listinfo/model-t <https://www.iab.org/mailman/listinfo/model-t>