Re: [Pearg] [saag] Ten years after Snowden (2013 - 2023), is IETF keeping its promises?

Dan Harkins <dharkins@lounge.org> Sun, 08 January 2023 09:32 UTC

Return-Path: <dharkins@lounge.org>
X-Original-To: pearg@ietfa.amsl.com
Delivered-To: pearg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 91327C14CE2F; Sun, 8 Jan 2023 01:32:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.01
X-Spam-Level:
X-Spam-Status: No, score=-5.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-3.114, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sUwd_GDypGSb; Sun, 8 Jan 2023 01:32:58 -0800 (PST)
Received: from www.goatley.com (www.goatley.com [198.137.202.94]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EA9A8C14F73D; Sun, 8 Jan 2023 01:32:57 -0800 (PST)
Received: from kitty.bergandi.net (cpe-76-176-14-122.san.res.rr.com [76.176.14.122]) by wwwlocal.goatley.com (PMDF V6.8 #2433) with ESMTP id <0RO504G5HUIX1J@wwwlocal.goatley.com>; Sun, 08 Jan 2023 03:32:57 -0600 (CST)
Received: from [192.168.1.153] (kitty.dhcp.bergandi.net [10.0.42.19]) by kitty.bergandi.net (PMDF V6.8 #2433) with ESMTPSA id <0RO50053YUIVZL@kitty.bergandi.net>; Sun, 08 Jan 2023 01:32:57 -0800 (PST)
Received: from customer.lsancax1.pop.starlinkisp.net ([98.97.57.68] EXTERNAL) (EHLO [192.168.1.153]) with TLS/SSL by kitty.bergandi.net ([10.0.42.19]) (PreciseMail V3.3); Sun, 08 Jan 2023 01:32:57 -0800
Date: Sun, 08 Jan 2023 01:32:55 -0800
From: Dan Harkins <dharkins@lounge.org>
In-reply-to: <CABcZeBPc0r275AiCL=qWTnzFT9PoQ9WMHz+GcmQZG8pgv2dmbw@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>, John Mattsson <john.mattsson@ericsson.com>
Cc: "ietf@ietf.org" <ietf@ietf.org>, "pearg@irtf.org" <pearg@irtf.org>, Vittorio Bertola <vittorio.bertola@open-xchange.com>, saag <saag@ietf.org>, "hrpc@irtf.org" <hrpc@irtf.org>
Message-id: <4fb59074-d604-ecd1-23bc-0df8651a7046@lounge.org>
MIME-version: 1.0
Content-type: text/plain; charset="UTF-8"; format="flowed"
Content-language: en-US
Content-transfer-encoding: 8bit
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.5.1
X-PMAS-SPF: SPF check skipped for authenticated session (recv=kitty.bergandi.net, send-ip=98.97.57.68)
X-PMAS-External-Auth: customer.lsancax1.pop.starlinkisp.net [98.97.57.68] (EHLO [192.168.1.153])
References: <HE1PR0701MB305098F652DBC34E3C40810B89F49@HE1PR0701MB3050.eurprd07.prod.outlook.com> <764163366.39904.1672842828297@appsuite-gw2.open-xchange.com> <CABcZeBNA_nJ2waQVENUvEXro91wAYOcH0ZxWqbLH4hoKcGkosw@mail.gmail.com> <9658281.42904.1672912808774@appsuite-gw2.open-xchange.com> <CA+9kkMBLiijcAyLYn_6h8z3N00EDaxdP=f7P2-qUt4Bn1iSWEg@mail.gmail.com> <HE1PR0701MB30505DC24A725E014D60FE0189FA9@HE1PR0701MB3050.eurprd07.prod.outlook.com> <CABcZeBPc0r275AiCL=qWTnzFT9PoQ9WMHz+GcmQZG8pgv2dmbw@mail.gmail.com>
X-PMAS-Software: PreciseMail V3.3 [230106] (kitty.bergandi.net)
X-PMAS-Allowed: system rule (rule allow header:X-PMAS-External noexists)
Archived-At: <https://mailarchive.ietf.org/arch/msg/pearg/n-b8KtdsoZZS3bdgYwEUPfTNI6M>
Subject: Re: [Pearg] [saag] Ten years after Snowden (2013 - 2023), is IETF keeping its promises?
X-BeenThere: pearg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Privacy Enhancements and Assessment Proposed RG <pearg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/pearg>, <mailto:pearg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pearg/>
List-Post: <mailto:pearg@irtf.org>
List-Help: <mailto:pearg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/pearg>, <mailto:pearg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Jan 2023 09:32:58 -0000


On 1/5/23 5:58 AM, Eric Rescorla wrote:
> [snip]
> 2. I agree that there are very significant threats to people's
> security and privacy at the endpoints, from a number of sources,
> including (1) software that was installed for users without their
> consent (2) software that they intended to install and does not behave
> the way that they expect and (3) direct attack on the software on
> their machines.

   What about (4) software that corporations require to be installed in
order for the devices to work properly? Google tracks users who have
google play installed with a 20min granularity [1] and if you've ever
tried installing a homebrew android on your phone and forgo google
play services you'll realize lots of useful apps will not work properly
without google play.

   It would be interesting to see a google version of the "Twitter Files"
to see how much this corporation that acquires such copious amounts
of PII cooperates with the very same LE/IC groups that Snowden
exposed.

   Dan.

[1] 
https://datatracker.ietf.org/meeting/108/materials/slides-108-pearg-tact-presentation-01

-- 
"The object of life is not to be on the side of the majority, but to
escape finding oneself in the ranks of the insane." -- Marcus Aurelius