[Mtgvenue] Re: is identification of individuals already covered by BCP 226
Ted Lemon <mellon@fugue.com> Thu, 26 March 2026 14:03 UTC
Return-Path: <mellon@fugue.com>
X-Original-To: mtgvenue@mail2.ietf.org
Delivered-To: mtgvenue@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4C207D1C9016 for <mtgvenue@mail2.ietf.org>; Thu, 26 Mar 2026 07:03:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=fugue.com header.b="yOZpGODR"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="zMceySrh"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 76i0IqK1G7ls for <mtgvenue@mail2.ietf.org>; Thu, 26 Mar 2026 07:03:05 -0700 (PDT)
Received: from fhigh-b4-smtp.messagingengine.com (fhigh-b4-smtp.messagingengine.com [202.12.124.155]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 991F0D1C9008 for <mtgvenue@ietf.org>; Thu, 26 Mar 2026 07:03:05 -0700 (PDT)
Received: from phl-compute-06.internal (phl-compute-06.internal [10.202.2.46]) by mailfhigh.stl.internal (Postfix) with ESMTP id 70C427A01D4; Thu, 26 Mar 2026 10:03:04 -0400 (EDT)
Received: from phl-imap-07 ([10.202.2.97]) by phl-compute-06.internal (MEProxy); Thu, 26 Mar 2026 10:03:04 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue.com; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm2; t=1774533784; x=1774620184; bh=OK0nKJ4N3A +UhRG/SIwS7U0h7IC+OrDAvbQ53R9ikxM=; b=yOZpGODR60uTP2cMiBd9Kg7RoL ZUO1Du+l4zWBGN1jqrnGhftyCQzxnvBnf4uRJpWktqtEeVZeP2P0MGdPNrwJoABZ Uf7+g9zhd9vJu08M+YUlR2eA3iTZAi2Ox6Wxb8YuGW6ywBg+3Bn/GSSM2yE1MxBC xgKI5bZUure3Vjzr2rX5EXTdoCv5zMu+ug0Zwa/LDI6UUVBSlWk02WyGmMBnX8s2 6c5cKibSABprX+h85FdXpw3xqtAA5P9S9N3dC8vKJqjLDUD4TDDy6iAUmOAUHFXh ZHjuuJH9zGxhy/xCqKLGPs/XrzpFhJF7oouqAHJNlt+aZ416WiytVNNscW+A==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t= 1774533784; x=1774620184; bh=OK0nKJ4N3A+UhRG/SIwS7U0h7IC+OrDAvbQ 53R9ikxM=; b=zMceySrhnMeRy51o+nXZvQP8a1CdIsYq3OIMRw4B82K1T6Vw527 tam+Nu4bXMCqQEg0hhwcBilSOHVQ4P22v+VK65HCjbEDTQgVYDk/ZpQ1835UxNZr fQM8Yj7GfwpFiXg8wxTE2zAEjdVydeEeXVe8+NlHE5JCJLpoboEZbnYemzDowhnY Ug1nxaY7S4toEwz40qjTugTa+LNHcyCi27yKbr0+PHHed8DpaamJ7AwIw705/NOV aJemWVDG6qVEbMHhO2T5BoLnguBd2fLsqEB8SM0FbxEfIMfnzi2eRbMl+M+D3Hq5 B7U0Y7k6MpXRKNVBciGBdgGFMjypWfT5DuA==
X-ME-Sender: <xms:lzzFafBj_spP2a2ka2t0TqwnGZstljq7lSMMLD_1q6xKihVgh_XjaA> <xme:lzzFaQUB6Rj1GPccb8bbxvTsqVZlHzInioNBJDHSqqkzsXYe9X8bCI-M5ZyQaBTAU unLO-OIcbont2UDv6A4nIYnst5mdjcdHZjfNb5PW_3Odsb7JcHCDWc>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgdefvdejheejucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmnecujf gurhepofggfffhvfevkfgjfhfutgesrgdtreerredtjeenucfhrhhomhepfdfvvgguucfn vghmohhnfdcuoehmvghllhhonhesfhhughhuvgdrtghomheqnecuggftrfgrthhtvghrnh epfeeugfdttdffkeefieejueduieevuefgvddvleeljedvjeejhedvtdfgleevudetnecu vehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepmhgvlhhloh hnsehfuhhguhgvrdgtohhmpdhnsggprhgtphhtthhopeegpdhmohguvgepshhmthhpohhu thdprhgtphhtthhopehrfihilhhtohhnsegtihhstghordgtohhmpdhrtghpthhtohepsh htvghphhgvnhdrfhgrrhhrvghllhestghsrdhttggurdhivgdprhgtphhtthhopehmthhg vhgvnhhuvgesihgvthhfrdhorhhgpdhrtghpthhtoheplhgvrghrsehlvggrrhdrtghh
X-ME-Proxy: <xmx:lzzFaZoScqtIz1cyTKUkuR2Qasb5tqej5ezJWT_DiWNi8U95jNvfYg> <xmx:lzzFaZdVYAePN7GdlnqZaUqeczICXm5btSAnj3kEJmGp5vEzU6XL6A> <xmx:lzzFaQpRXzdohzUOdy4eC5qLi2WjDCywXFE91j_FwFZVSjx1YlSrqg> <xmx:lzzFaSHLMuYVYklLa3aKvJKClqguSZwRTZ8NkZWcDZWfCTwedxk44Q> <xmx:mDzFaaxdGjn5A4pkNhnYapD3xsKFAJpqYX6Mmc6frRrAYMb4KY35T0C3>
Feedback-ID: i1136489e:Fastmail
Received: by mailuser.phl.internal (Postfix, from userid 501) id 530991EA006C; Thu, 26 Mar 2026 10:03:03 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
MIME-Version: 1.0
X-ThreadId: A-t3LnA8zzbg
Date: Thu, 26 Mar 2026 15:02:35 +0100
From: Ted Lemon <mellon@fugue.com>
To: "Rob Wilton (rwilton)" <rwilton@cisco.com>
Message-Id: <0f8d450d-6b6a-45ee-a9a9-d831d8df69a9@app.fastmail.com>
In-Reply-To: <LV8PR11MB8536AAB9B87E1503CB21F67CB556A@LV8PR11MB8536.namprd11.prod.outlook.com>
References: <840d7976-9813-4c15-887a-7588499bff44@lear.ch> <aded34d9-e05c-4f0e-96db-d3d2dde0493d@cs.tcd.ie> <a1f494a4-e065-4e69-8ebb-2dcdfef5bec1@lear.ch> <9e92fb62-209c-4a6d-90ea-c9f05802019a@cs.tcd.ie> <LV8PR11MB853677CCE7973B6BB0399AD5B556A@LV8PR11MB8536.namprd11.prod.outlook.com> <60B23843-192B-442D-9F3A-17CE29E0CA33@fugue.com> <LV8PR11MB8536AAB9B87E1503CB21F67CB556A@LV8PR11MB8536.namprd11.prod.outlook.com>
Content-Type: multipart/alternative; boundary="41779efdf6f9425692efb25ea0d71080"
Message-ID-Hash: 5554UEEFBFQ2ME33IHJ24LQU52DJ4VLA
X-Message-ID-Hash: 5554UEEFBFQ2ME33IHJ24LQU52DJ4VLA
X-MailFrom: mellon@fugue.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-mtgvenue.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Eliot Lear <lear@lear.ch>, "mtgvenue@ietf.org" <mtgvenue@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Mtgvenue] Re: is identification of individuals already covered by BCP 226
List-Id: "List for email discussion of the IETF meeting venue selection process." <mtgvenue.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/mtgvenue/XGlhwi0GuslNWiWTM3Oc5xZ3lVM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mtgvenue>
List-Help: <mailto:mtgvenue-request@ietf.org?subject=help>
List-Owner: <mailto:mtgvenue-owner@ietf.org>
List-Post: <mailto:mtgvenue@ietf.org>
List-Subscribe: <mailto:mtgvenue-join@ietf.org>
List-Unsubscribe: <mailto:mtgvenue-leave@ietf.org>
You’re missing my point. My point is that we are saying what we want from the IETF. We are not saying what we want from random governments. Of course the IETF isn’t secretly exfiltrating our data. But if it were, us saying we don’t want that would still matter. Similarly, governments could secretly exfiltrate the data without our permission. Us making them do it secretly rather than openly still matters in terms of the risks participants face. So the fact that these attacks are possible has no bearing on what we may or may not want the IETF to do. They are two separate issues. On Thu, Mar 26, 2026, at 2:38 PM, Rob Wilton (rwilton) wrote: > Hi Ted, > > I don't think that this is at all about the IETF network really. I'm 99% convinced that the IETF network is designed/run to minimise data collection, and any data that is collected, e.g., to diagnose an issue, would be wiped shortly after the meeting anyway. Probably this is already explicitly stated somewhere. Nor am I suggesting that any of the folks running the IETF network would be nefariously capturing data, but my point was that there has been supply chain attacks against network hardware in the past, so that is also a plausible attack vector here for any really determined country/adversary. > > I really see this discussion as being just down to the regulatory requirements of where we hold meetings, and the choice is a fairly simple one: Should we go to places where there is less privacy of participant network usage vs the other potential benefits of visiting more countries that cover a wider proportion of the IETF participant base? > > I'm also happy if we say that we should prefer to go to places that preserve more network privacy, although I don't know what weighting should be given to that consideration compared to the various other competing concerns when making venue selection, and I'm not sure how prescriptive on more network privacy we should be. > > I do, I think, have a problem with making the guidance and restrictions too strict (e.g. MUST/MUST NOT) because I'm not sure whether that is really the right choice (e.g., concerning the recent meeting in China), and as others have pointed out this could accidentally start including some other countries that we would normally consider as being okay locations to meet. > > And I do have concerns that, with widespread usage of VPNs, the actual risk of this data capture is being overstated. > > Kind regards, > Rob > > > > *From: *Ted Lemon <mellon@fugue.com> > *Date: *Thursday, 26 March 2026 at 12:32 > *To: *Rob Wilton (rwilton) <rwilton=40cisco.com@dmarc.ietf.org> > *Cc: *Stephen Farrell <stephen.farrell@cs.tcd.ie>, Eliot Lear <lear@lear.ch>, mtgvenue@ietf.org <mtgvenue@ietf.org> > *Subject: *[Mtgvenue] Re: is identification of individuals already covered by BCP 226 > On 26 Mar 2026, at 12:56, Rob Wilton (rwilton) <rwilton=40cisco.com@dmarc.ietf.org> wrote: >> If a participant was particularly concerned, then would they be able to trust all the network equipment being used to run the network? Would such individuals really want to trust the security of the IETF network to such an extent? Wouldn't they just attend remotely if the risks were real and significant? > > Of course that's also a risk. However, it's a risk we probably don't control. Certainly we also can't control the risk if the IETF behind our backs captures the data and delivers it to the authority without telling us and without our permission. > > What we are arguing about is what we believe the IETF should do. E.g. if the IETF doesn't hand over the RADIUS logs, that makes it harder to get the information, and also in some jurisdictions means that the acquisition of the information is covered by different legal rules, and this can be protective for individuals EVEN IF the data is acquired by the attacker. > > The question is, "do we want the IETF to be a weak link here?" not "if we did the right thing here, would that reduce participants' exposure to zero?" > > If your answer is "meh, we will could easily just secretly steal your data anyway so why worry?" then I think you're really taking a very unfortunate position that I certainly don't agree with. >
- [Mtgvenue] is identification of individuals alrea… Eliot Lear
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Eliot Lear
- [Mtgvenue] Re: is identification of individuals a… Rob Wilton (rwilton)
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Rob Wilton (rwilton)
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Ted Lemon
- [Mtgvenue] Re: is identification of individuals a… Rob Wilton (rwilton)
- [Mtgvenue] Re: is identification of individuals a… Ted Lemon
- [Mtgvenue] Re: is identification of individuals a… Livingood, Jason
- [Mtgvenue] Re: is identification of individuals a… Eric Rescorla
- [Mtgvenue] Re: is identification of individuals a… Christian Huitema
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Eric Rescorla
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Vittorio Bertola
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Eliot Lear
- [Mtgvenue] Re: is identification of individuals a… Rob Wilton (rwilton)
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Ted Lemon
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Rob Wilton (rwilton)
- [Mtgvenue] Re: is identification of individuals a… Brian E Carpenter
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Livingood, Jason
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… John C Klensin
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Eric Rescorla
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Michael Richardson
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… S Moonesamy
- [Mtgvenue] Re: is identification of individuals a… stndrds-inacio stndrds-inacio
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… stndrds-inacio stndrds-inacio
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Eric Rescorla
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… stndrds-inacio stndrds-inacio
- [Mtgvenue] Re: is identification of individuals a… Vittorio Bertola
- [Mtgvenue] Re: is identification of individuals a… Ted Lemon
- [Mtgvenue] Re: is identification of individuals a… S Moonesamy
- [Mtgvenue] Re: is identification of individuals a… Dhruv Dhody
- [Mtgvenue] Re: is identification of individuals a… Livingood, Jason
- [Mtgvenue] Re: is identification of individuals a… S Moonesamy
- [Mtgvenue] Re: is identification of individuals a… Livingood, Jason
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… S Moonesamy
- [Mtgvenue] Re: is identification of individuals a… Eliot Lear
- [Mtgvenue] Re: is identification of individuals a… Jay Daley
- [Mtgvenue] Re: is identification of individuals a… Brian E Carpenter
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Brian E Carpenter
- [Mtgvenue] Re: is identification of individuals a… Toerless Eckert
- [Mtgvenue] Re: is identification of individuals a… Rob Sayre
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Rob Sayre
- [Mtgvenue] Re: is identification of individuals a… Stephen Farrell
- [Mtgvenue] Re: is identification of individuals a… Rob Sayre
- [Mtgvenue] Re: is identification of individuals a… Rob Sayre
- [Mtgvenue] Re: is identification of individuals a… stndrds-inacio stndrds-inacio
- [Mtgvenue] Re: is identification of individuals a… Rob Sayre