[Modern] Kathleen Moriarty's Discuss on draft-ietf-modern-problem-framework-03: (with DISCUSS and COMMENT)

Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com> Thu, 22 February 2018 02:51 UTC

Return-Path: <Kathleen.Moriarty.ietf@gmail.com>
X-Original-To: modern@ietf.org
Delivered-To: modern@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D74B128959; Wed, 21 Feb 2018 18:51:15 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-modern-problem-framework@ietf.org, modern-chairs@ietf.org, srdonovan@usdonovans.com, modern@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.72.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151926787492.21271.961401229922724643.idtracker@ietfa.amsl.com>
Date: Wed, 21 Feb 2018 18:51:14 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/modern/2NOo7MJXnbMOavyofbSEbWOkxTQ>
Subject: [Modern] Kathleen Moriarty's Discuss on draft-ietf-modern-problem-framework-03: (with DISCUSS and COMMENT)
X-BeenThere: modern@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "Managing, Ordering, Distributing, Exposing, & Registering telephone Numbers non-WG discussion list" <modern.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/modern>, <mailto:modern-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/modern/>
List-Post: <mailto:modern@ietf.org>
List-Help: <mailto:modern-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/modern>, <mailto:modern-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Feb 2018 02:51:15 -0000

Kathleen Moriarty has entered the following ballot position for
draft-ietf-modern-problem-framework-03: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-modern-problem-framework/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

I agree with the SecDir reviewer that a Privacy Considerations section is
needed.  What user data is potentially exposed?  4.3.4 talks about government
access, who else has access?  What concerns are there about the data that is
shared?  What if one of the involved systems is compromised and data is stolen?

It's a well written draft, this appears to be a gap and I didn't see a response
to the SecDir review.  Thanks in advance.

https://mailarchive.ietf.org/arch/msg/secdir/1WiFmubNoAKo3qAhNu4be35g10w


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I'm a little surprised to see section 4.3.4 instead of just a statement on how
authorized access to the data is provided.