Re: [Model-t] Next steps from Tuesday's breakfast meeting

"Rezaki, Ali (Nokia - DE)" <ali.rezaki@nokia.com> Thu, 21 November 2019 05:53 UTC

Return-Path: <ali.rezaki@nokia.com>
X-Original-To: model-t@ietfa.amsl.com
Delivered-To: model-t@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54D811209EB for <model-t@ietfa.amsl.com>; Wed, 20 Nov 2019 21:53:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CY7G8s_9_l3P for <model-t@ietfa.amsl.com>; Wed, 20 Nov 2019 21:53:49 -0800 (PST)
Received: from EUR02-AM5-obe.outbound.protection.outlook.com (mail-eopbgr00093.outbound.protection.outlook.com [40.107.0.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 867721209F5 for <model-t@iab.org>; Wed, 20 Nov 2019 21:53:48 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=XgcZ06v5cZLx+0JExncZvhmjF04mDCySzctdJNQv1RO1JKQXLkjmKDKaQxZF4jCvgj7ZwaNvzNBawl7HoKNyQGRJWpvcBawBHd+Jay1BA4QydDI5MLoOIU87zlTn3zzGis0Iu9XSp8n+BgGEfJkKKfQYgGm9nYJfQhJy5IX3nuPXBhTZdFW7lIxGbD+hK7j+8SYA9QkozUEnC7MoSyOziBd8l8NCx9wVyiFiQTEZvHzvTekFMXUo6+hCM35YnmX4ruCEiSPD9vxg0ZFrXgSKKqMwNGmtpXQQahaC7GshXqpfquy0s+5FSxdBLZ0XyQtXfQAR6B39FvMshK1tddYn3g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rg7Y8M84QzUn+8nj/TRc3R03fVLw34+p5IL42SIJh6M=; b=AlcQy9o04/LUwCTVTQS7xni1k15jHwZur7wt4US3iB/rHniujoJHBIBOHLsKWhswiAojteE1M7sPHomScqdtQrmL33FMzIBuLNr9vFqHe1DIV7rFBTPg5l3qEgbMZQLVL+FbehYtf19aQg0BtzzMkGcnICNJETdutXHghl173t7E97HJZ/dUgaKTlP3RUoX13SlfDcl525UFuysBWRjAVRMI21HwtXx6wlfoR/528vei4BlFC5sHuvCsI7aFd6mz60EqT+7hokUIGooDVzc2vfSPObMrMXaDBOQ/I/ZrX+Yq0znP+msfgBm2Le6XxjecqhfVUCE3U/Jz25fyAoCorQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rg7Y8M84QzUn+8nj/TRc3R03fVLw34+p5IL42SIJh6M=; b=MJ7M3YvfnFUlRjYz/JAjW7sJHUaEN3mVCE4uiIDNfReGai7p9G11tK+2u8JjxbheS5Vqmob8QgBxLAuHMKsN/edHwKt2z+vXmaqfvgnYJGJ3M9bkR9/Wb02AEHcyfD2+dC8MpAJcbCS0+VBFnPF2fOgTx7o8VfkMuDtp+E/F3hM=
Received: from HE1PR0701MB2953.eurprd07.prod.outlook.com (10.168.95.140) by HE1PR0701MB2124.eurprd07.prod.outlook.com (10.168.35.142) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.7; Thu, 21 Nov 2019 05:53:45 +0000
Received: from HE1PR0701MB2953.eurprd07.prod.outlook.com ([fe80::e9a2:f4a5:1c3e:3666]) by HE1PR0701MB2953.eurprd07.prod.outlook.com ([fe80::e9a2:f4a5:1c3e:3666%12]) with mapi id 15.20.2474.019; Thu, 21 Nov 2019 05:53:45 +0000
From: "Rezaki, Ali (Nokia - DE)" <ali.rezaki@nokia.com>
To: Robin Wilton <wilton@isoc.org>, "model-t@iab.org" <model-t@iab.org>
Thread-Topic: Next steps from Tuesday's breakfast meeting
Thread-Index: AQHVoByfkraxj2f4GkybE72px9ojnqeVG/8Q
Date: Thu, 21 Nov 2019 05:53:45 +0000
Message-ID: <HE1PR0701MB29533B9D2AEB53A6BE026B92934E0@HE1PR0701MB2953.eurprd07.prod.outlook.com>
References: <A35A9A80-80A4-41A4-8C9B-4A964D565854@isoc.org>
In-Reply-To: <A35A9A80-80A4-41A4-8C9B-4A964D565854@isoc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=ali.rezaki@nokia.com;
x-originating-ip: [31.133.138.95]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: c7fd8e51-717e-44e4-a9ba-08d76e472bf5
x-ms-traffictypediagnostic: HE1PR0701MB2124:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <HE1PR0701MB212486AD1E1C3B29946282E2934E0@HE1PR0701MB2124.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0228DDDDD7
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(346002)(376002)(396003)(39860400002)(366004)(136003)(53754006)(199004)(189003)(26005)(5660300002)(6506007)(53546011)(186003)(71200400001)(81166006)(66446008)(446003)(476003)(6246003)(66476007)(14454004)(11346002)(86362001)(71190400001)(102836004)(8676002)(486006)(14444005)(6306002)(66066001)(2906002)(55016002)(9686003)(54896002)(8936002)(478600001)(25786009)(256004)(110136005)(99286004)(229853002)(6116002)(64756008)(81156014)(7736002)(66946007)(66574012)(2501003)(7696005)(76176011)(3846002)(76116006)(790700001)(52536014)(74316002)(6436002)(66556008)(316002)(33656002); DIR:OUT; SFP:1102; SCL:1; SRVR:HE1PR0701MB2124; H:HE1PR0701MB2953.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: nokia.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: YWas9CKpQuxgY0Qb+5SF8s2NY44xph4i1GqZw57MYym6atEuoShIzbStkh2kwg/58MOS2Drg/wG3Tu8Y7ydPmbljPhaCo/JyqMSB9BCY4zNil9YupbYnTBcMzh+MmZyqUmq3ZYHcUnajay8clmj66DmSXLqnaAUrffD5mF6n2NPYv9/Th++QgtnK06qEE3rDd3mvxGR2U5MLHlQOCxxnuqzEJyEqmXKgFveZ0wj8CsgFPXtg8dJwMXo3Hu+axziISkbEL3o7WmN9V5MCmM4FMQoBb80iklQWVhYKKJDX+1naSyJGEdEpYLUWlrpgxuw/gt6/B8IeM/MUjrSOhLfNczClLZ3Aixigk7u7mami7z5bARu+/5Z79FRyY7ya9Dyfp8Czal7mSdwoNbrUuYWgumqJiI5VyQIJmCZyqszthtyemKTXfQRy5NL1s+p84Czm
Content-Type: multipart/alternative; boundary="_000_HE1PR0701MB29533B9D2AEB53A6BE026B92934E0HE1PR0701MB2953_"
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c7fd8e51-717e-44e4-a9ba-08d76e472bf5
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Nov 2019 05:53:45.3838 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 426djMeoKvGkak3GDTmwV58nL7vylv/aIZEy9Aa+37rr2bth7tPWec1Ujlf+jliK0NdA7IN4Eyr4ntyDW39ojw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2124
Archived-At: <https://mailarchive.ietf.org/arch/msg/model-t/scADT-mJXJ6S-EhrfLbks34wY0o>
Subject: Re: [Model-t] Next steps from Tuesday's breakfast meeting
X-BeenThere: model-t@iab.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions of changes in Internet deployment patterns and their impact on the Internet threat model <model-t.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/model-t>, <mailto:model-t-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/model-t/>
List-Post: <mailto:model-t@iab.org>
List-Help: <mailto:model-t-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/model-t>, <mailto:model-t-request@iab.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Nov 2019 05:53:54 -0000

Hello Robin, All,

Thanks very much for our Tuesday morning meeting and for the summary of the follow-up actions.

Just a short update on my action item please:

Ali R: Document the attacks that exploited vulnerabilities in IETF protocol specifications, covering also implementation and deployment vulnerabilities that modified specifications might have mitigated; starting with a survey of the CVE database.

Safe travels all.

Best regards,

Ali


From: Model-t <model-t-bounces@iab.org> On Behalf Of Robin Wilton
Sent: Thursday, November 21, 2019 4:35 AM
To: model-t@iab.org
Subject: [Model-t] Next steps from Tuesday's breakfast meeting

Hi everyone, and thank you Dominique for listing those follow-up actions.
I noted a few more, though they were of varying degrees of firmness/detail…

Please would those identified in the list below check to see if I have misrepresented their intent, and correct as appropriate?


Agenda Item 1.3: Who, when

Contributions:

  *   Stephen F, Jari A: continue draft
  *   Dominique L: continue draft
  *   Ali R: survey of CDEs, collate some data about threats
  *   Dirk K: will write up the thing he’s going to write up (!)
  *   Tommy C: “aware of”: CLES endpoints draft; malware study
  *   Robin W: will be producing a high-level vulnerability analysis in "crypto as a system” materials (1H2020, probably 1Q2020)
  *   Christian H: will write up a couple of attack scenarios
  *   Melinda S: trust comes from different sources in the world of decentralised apps, and that isn’t coming to the IETF… will write something
            Other:
                        [Carsten B: IoT RG will be keeping an eye on thi as it evolves]
                        [JA: “trust boundaries” - would MT or EKR contribute?]

  *   MT - I have a half written thing


Timing:

  *   Interim call in late Jan/Feb
  *   Deferred decision on whether to meet at IETF107 (Vancouver, March 2020)



Best wishes,
Robin Wilton