Re: [Model-t] Minimization

Christian Huitema <huitema@huitema.net> Thu, 17 March 2022 19:18 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: model-t@ietfa.amsl.com
Delivered-To: model-t@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 421E23A0915 for <model-t@ietfa.amsl.com>; Thu, 17 Mar 2022 12:18:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iz7A8o9cNtKH for <model-t@ietfa.amsl.com>; Thu, 17 Mar 2022 12:18:24 -0700 (PDT)
Received: from mx36-out10.antispamcloud.com (mx36-out10.antispamcloud.com [209.126.121.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 014BB3A085E for <model-t@iab.org>; Thu, 17 Mar 2022 12:18:23 -0700 (PDT)
Received: from xse424.mail2web.com ([66.113.197.170] helo=xse.mail2web.com) by mx258.antispamcloud.com with esmtp (Exim 4.92) (envelope-from <huitema@huitema.net>) id 1nUvdb-000GeD-Nx for model-t@iab.org; Thu, 17 Mar 2022 20:18:22 +0100
Received: from xsmtp21.mail2web.com (unknown [10.100.68.60]) by xse.mail2web.com (Postfix) with ESMTPS id 4KKH3t0F1kz9wm for <model-t@iab.org>; Thu, 17 Mar 2022 12:18:18 -0700 (PDT)
Received: from [10.5.2.49] (helo=xmail11.myhosting.com) by xsmtp21.mail2web.com with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.92) (envelope-from <huitema@huitema.net>) id 1nUvdZ-0001Fx-Tu for model-t@iab.org; Thu, 17 Mar 2022 12:18:17 -0700
Received: (qmail 7735 invoked from network); 17 Mar 2022 19:18:16 -0000
Received: from unknown (HELO [192.168.1.105]) (Authenticated-user:_huitema@huitema.net@[172.58.46.247]) (envelope-sender <huitema@huitema.net>) by xmail11.myhosting.com (qmail-ldap-1.03) with ESMTPA for <ietf@kuehlewind.net>; 17 Mar 2022 19:18:16 -0000
Message-ID: <db42a753-9100-e5c8-f4a6-bd076a5b4d42@huitema.net>
Date: Thu, 17 Mar 2022 12:18:16 -0700
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.7.0
Content-Language: en-US
To: Mirja Kuehlewind <ietf@kuehlewind.net>, Martin Thomson <mt@lowentropy.net>
Cc: Russ White <russ@riw.us>, Jari Arkko <jari.arkko@piuha.net>, model-t@iab.org
References: <2af931d1-2763-46d3-a616-7ac79ae3b082@www.fastmail.com> <3A5051E5-ACFC-4547-973F-E250B17AC58B@piuha.net> <023601d83947$076991d0$163cb570$@riw.us> <67e54986-ba88-4ff7-a542-3805a4e58679@www.fastmail.com> <1735A9DF-3F09-47B8-97E8-0608C9787FC6@kuehlewind.net>
From: Christian Huitema <huitema@huitema.net>
In-Reply-To: <1735A9DF-3F09-47B8-97E8-0608C9787FC6@kuehlewind.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Originating-IP: 66.113.197.170
X-Spampanel-Domain: xsmtpout.mail2web.com
X-Spampanel-Username: 66.113.197.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=66.113.197.0/24@xsmtpout.mail2web.com
X-Spampanel-Outgoing-Class: unsure
X-Spampanel-Outgoing-Evidence: Combined (0.15)
X-Recommended-Action: accept
X-Filter-ID: Pt3MvcO5N4iKaDQ5O6lkdGlMVN6RH8bjRMzItlySaT9WLQux0N3HQm8ltz8rnu+BPUtbdvnXkggZ 3YnVId/Y5jcf0yeVQAvfjHznO7+bT5xtaXA79M6yv3Jd2jGX2j1xQ7fEPDO+qSCmuyj2YTPdOyhY +l0Uaa7GgrZhDjqiCekh55uqY3MhMgFAHq5BxPxPXn36fLqvhISQ5ykyqUZqUd1jhnM/Mbva2XLV /LIEzaL2KoAZhJekBPedneT7f699lUvGL3YfqVlqymmgnSMJBIPAgTtUp75uqlx0KezvZHU8jaTA 4gvoN3cy3ZS3bc6iWQaaSSaRcFTFxaRvADgOuFdAU5fRzM/QzQW9/IoH33AG8ECuCwECazCwODtO F78PiyQEs+dlGXUJLWZ+Gc08Nmllke3azHdKmySKNUVQl4ntlVxnbS8qIO7oudHyb2T1VQ58xe/l rqiRGalI3YPsxOTrFXToVyBmRCgQVX6zVyFUu8qzeMQP6uTHL0d9UjfY+eX5ZvcELCIKs663F/co VFYFvf25LVONYbYifH5OzZDcG6hsRQZiAIgw+z837AqgX7ewI8e1h7RITgN14BHmGVt/ReJ9Mfhz zmbKTH7wI9GEU1utNskUAORCV2WFZX0jVtchDyr/klHhR+7g04zYe6TeVLW3pB0Q/PTyowo5Afvn cAhhRENGPJ4TlBPaDz9pCFXoGKtafvOtcW/mP16byrL/nwvREHuP3/Ps3A4Pt7hRyBl07OVp2D/S 9ogT8aIX6abOyKlLsxs8P4CT3FEuG9QoXOoulHZJNrrjY/ruNIWC1AI9a3irbifzymzQYX+PCoIe iDd5LHTNKTf5H67vi9UoSN+Z3xdSCf5b5b26iRyKuZkMyFBGaEBYeh6pTEjU1i4/yBTqzRgSDNyj idubhn6m+UeFXprlCOm3BAEbJtAT1BYHStA0OogdNtRxnRSLF+XCKxIG9XMEgRDdaWpvCv+zESlk TxdSCNcDfRohcehWBb39uS1TjWG2Inx+Ts2QNOYPIz4ynMa7pZQ4hi/HGtuWeHzx9sLaQmDwvYQn 76e9NXttZBkk6PeFqH6So31P
X-Report-Abuse-To: spam@quarantine11.antispamcloud.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/model-t/uck29tgnjJDBiMvqmzDfXE4rKfE>
Subject: Re: [Model-t] Minimization
X-BeenThere: model-t@iab.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions of changes in Internet deployment patterns and their impact on the Internet threat model <model-t.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/model-t>, <mailto:model-t-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/model-t/>
List-Post: <mailto:model-t@iab.org>
List-Help: <mailto:model-t-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/model-t>, <mailto:model-t-request@iab.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Mar 2022 19:18:25 -0000

On 3/17/2022 11:12 AM, Mirja Kuehlewind wrote:
> I agree these are good points!
>
> I also just had a quick read and to me it seem that there might also be a point about identity. Often information is only sensitive if it can be associated to a certain identify, so providing data in an anonymous way whenever possible might also be a good approach. Not sure if this belongs in this document or if that is a separate point….


Yes, but there are also many examples of allegedly anonymized datasets 
that were then shown to contain enough information to identify the 
subjects. If we want to say something like that, then we need to be 
rather cautious, and distinguish between statistics and hidden 
identities. Saying "out of 1,000,000 connections, we observed that 10% 
had a delay larger than 100 ms" is one thing. Having data on individual 
sessions, even without explicitly storing PII, is another.

The flip side of that is of course debugging. It is hard to debug a 
complex failure without extensive data, such as a trace of all packets 
in a connection...

-- Christian Huitema