Re: [Pearg] [saag] Ten years after Snowden (2013 - 2023), is IETF keeping its promises?

Dino Farinacci <farinacci@gmail.com> Wed, 04 January 2023 19:58 UTC

Return-Path: <farinacci@gmail.com>
X-Original-To: pearg@ietfa.amsl.com
Delivered-To: pearg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F4E0C1522AA; Wed, 4 Jan 2023 11:58:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yubGHMnToRaK; Wed, 4 Jan 2023 11:58:14 -0800 (PST)
Received: from mail-pj1-x1031.google.com (mail-pj1-x1031.google.com [IPv6:2607:f8b0:4864:20::1031]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64208C14F74E; Wed, 4 Jan 2023 11:58:14 -0800 (PST)
Received: by mail-pj1-x1031.google.com with SMTP id c8-20020a17090a4d0800b00225c3614161so32850848pjg.5; Wed, 04 Jan 2023 11:58:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=KJy4pxWhJQ04g2gk4MNDbfguDjXO5D+uIqjJe9t9mvg=; b=CRBvQOPyigb49St2qaKi3eKdQM0Mi1Un8pl+/sg7v8P//HepKwfzmcA/qLZNed3vYT dCPSGRY21prUZOHuoYUPNTKdffcbAWsA1c3dOQKGXdwLSVS++yI2LmhuXiDWkofbdDUo mzvR9MYnI6yupGePeIqUwKZb2zcaHz0eSweNscETgpR46522D0U2Zzxu6IPEEHLIQdvx aciptoWE36otGwwsw+fn6pP7YKTG7HrdWt+V7WFoKBxoamPoEsOsjgpWurQpS37um30C kyOhTxhu+isgokfL6qhMc/cnZJOhimHuxShgRCx+IW7yTXbUsh5ljROnWJav5J4Uy72x VKLA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=KJy4pxWhJQ04g2gk4MNDbfguDjXO5D+uIqjJe9t9mvg=; b=cYcIPhRlSyFWcvFu14RLsfdgBKpfO8cOgH8fmXtSW0l2msNe7bJd3V/ifxHVdrBPT4 mwvVGngSLobpKgiGY2ysIaX/nY+BtNNO9p6SbQ9ya+vkvW+46DCeA9+1fAW7KnqSgeQ9 8Q3JrGJyLn8AyU8N6DJ0+l9KoAxmS75VkTRuZmF/tAfqe6h0CykePutXdeebIWL31G4D 0kvGn55tdluHddeqqD4HkcseABNk42m6yohnm0xD6mitDj0KgvxigEFlNaxOsFbRq6zr Y3kshE5lMmaVw88HmSXzxQoillnCJd9OLE5t/CE0MQ9Pevh8bkQuyodTvrRxNlIsTwkd EtDA==
X-Gm-Message-State: AFqh2kq1yO24PJ3HfuVCA7zpryEA5E6TAa1d3exWf3hlWeHA7u5lgMUI LNaWxQIXnoF2kV7Bf0QeOqk=
X-Google-Smtp-Source: AMrXdXt0dzs7bo74qZUyU0aiuX43UQ7gRtUODKO8f8dVsPfZbl7pZwhdk8YsW1IDxvclC/8SphbVXQ==
X-Received: by 2002:a17:902:c40f:b0:189:d4c5:f155 with SMTP id k15-20020a170902c40f00b00189d4c5f155mr70507588plk.63.1672862294002; Wed, 04 Jan 2023 11:58:14 -0800 (PST)
Received: from smtpclient.apple (c-98-234-33-188.hsd1.ca.comcast.net. [98.234.33.188]) by smtp.gmail.com with ESMTPSA id h10-20020a170902f7ca00b0019145e3f77dsm6942889plw.111.2023.01.04.11.58.13 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 04 Jan 2023 11:58:13 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
From: Dino Farinacci <farinacci@gmail.com>
In-Reply-To: <CAKr6gn0tFXEV-h7LH1_Ts5iQRw_mGEi=TqS7hsyK-SqDFmmY-A@mail.gmail.com>
Date: Wed, 04 Jan 2023 11:58:12 -0800
Cc: Lloyd W <lloyd.wood=40yahoo.co.uk@dmarc.ietf.org>, Antoine FRESSANCOURT <antoine.fressancourt=40huawei.com@dmarc.ietf.org>, IETF Discussion Mailing List <ietf@ietf.org>, pearg@irtf.org, John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, saag <saag@ietf.org>, hrpc@irtf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <4E6658C5-4328-4A59-83E5-289D521837ED@gmail.com>
References: <3c3230f3783b4ec9a8a9e3bb87cc2a8d@huawei.com> <08C49067-DB4C-41AB-A6F3-B96BDBE0A4BC@yahoo.co.uk> <CAKr6gn0tFXEV-h7LH1_Ts5iQRw_mGEi=TqS7hsyK-SqDFmmY-A@mail.gmail.com>
To: George Michaelson <ggm@algebras.org>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/pearg/XVwTkWZU2d85O18J5naae3FPuug>
Subject: Re: [Pearg] [saag] Ten years after Snowden (2013 - 2023), is IETF keeping its promises?
X-BeenThere: pearg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Privacy Enhancements and Assessment Proposed RG <pearg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/pearg>, <mailto:pearg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pearg/>
List-Post: <mailto:pearg@irtf.org>
List-Help: <mailto:pearg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/pearg>, <mailto:pearg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Jan 2023 19:58:16 -0000

> Put a nonce source ip in the packet header and the real source as 4-16 bytes of PFS protected payload. 

And only keep using the nonce per transport connection? That is, each new connection, TCP, UDP session, or QUIC would bet a new nonce source IP?

Dino