Re: [perpass] "Its an attack" BCP draft

Phillip Hallam-Baker <hallam@gmail.com> Thu, 21 November 2013 15:34 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA2481ADFB6 for <perpass@ietfa.amsl.com>; Thu, 21 Nov 2013 07:34:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nN0tiMr77G1Q for <perpass@ietfa.amsl.com>; Thu, 21 Nov 2013 07:34:41 -0800 (PST)
Received: from mail-la0-x236.google.com (mail-la0-x236.google.com [IPv6:2a00:1450:4010:c03::236]) by ietfa.amsl.com (Postfix) with ESMTP id B1F101ADFA5 for <perpass@ietf.org>; Thu, 21 Nov 2013 07:34:40 -0800 (PST)
Received: by mail-la0-f54.google.com with SMTP id ev20so8791256lab.27 for <perpass@ietf.org>; Thu, 21 Nov 2013 07:34:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=znNDSHRpyayQmF7MuzqKCQ6BTRUCfP39hp6cb/fZGDA=; b=iSxmk6Ia+ngIN9pESbLmAhkkmjrikECMQI7h4vzH1UM7022Ig0gKZ9UxbmerIkCPFv rjg/C+S+ivboGPxKZUxYvPXc2ysZzPK2n1yrLYnn9ZgCH7pywYSnv4VmmkGV+2ZRMytl uUnrxaxG0HSxQdSv54KB5gYlLp4HR+MV827fQywO9Qb+9GfD5yYuz/nrFqYKh0CfYqW2 q9hJ/ZhESQMHCHmKDh1Us4Hy/6dH6vXw8pbPaMvzuYHB/tsj+qklBSD7DxOjWX6C0m6A I6bLLcISx7tUDQu28Sh0MIVJ8nGmvIGgN4cYqDFQLLQB5YznvwIZarWYBEMeeqssoM1j psag==
MIME-Version: 1.0
X-Received: by 10.152.23.167 with SMTP id n7mr82509laf.56.1385048070483; Thu, 21 Nov 2013 07:34:30 -0800 (PST)
Received: by 10.112.46.98 with HTTP; Thu, 21 Nov 2013 07:34:30 -0800 (PST)
In-Reply-To: <223EC5F4-94E8-4507-95DB-56295F72FBB0@checkpoint.com>
References: <528D34D7.1010303@cs.tcd.ie> <CA+BZK2pKpbJaGNWOeM22QQ1kVBdXuxAz99eX4jBz38HqWOBVjQ@mail.gmail.com> <223EC5F4-94E8-4507-95DB-56295F72FBB0@checkpoint.com>
Date: Thu, 21 Nov 2013 10:34:30 -0500
Message-ID: <CAMm+LwgnJp9N++kWdhi9bbYmOpLAjwx7Taz6HQ3ggDMBRtAmSA@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Yoav Nir <ynir@checkpoint.com>
Content-Type: multipart/alternative; boundary="089e0160a5e63cf62304ebb1a227"
Cc: perpass <perpass@ietf.org>, Ralf Skyper Kaiser <skyper@thc.org>
Subject: Re: [perpass] "Its an attack" BCP draft
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Nov 2013 15:34:43 -0000

On Thu, Nov 21, 2013 at 8:58 AM, Yoav Nir <ynir@checkpoint.com> wrote:

>
> On Nov 21, 2013, at 1:47 PM, Ralf Skyper Kaiser <skyper@thc.org> wrote:
>
> > Hi,
> >
> > "...pervasive monitoring significantly more expensive or infeasible"
> >
> > Recommend to remove 'significantly'. (otherwise there will be an
> argument what 'significant' means. 1M USD? 10M USD? And how expensive is it
> anyway to send a RST to 240M users? 1 cent? 1 Dollar?).
>
> I agree there will be an argument. But don't you think we need some
> criterion for defining success?  If we increase the cost 1000x, they have
> to totally change their operating model. If we increase the cost 10x, they
> will have to scale back what they're doing. If we increase it 1.5x?
>  Probably just makes the American tax payer pay a little more.
>
>
The criteria that is used inside the NSA is GDP of adversary * number of
years.


Which is about $10 Trillion * 10 = $100 Trillion

Which sounds a lot but we have billions of communications a day. So raising
the attack cost to $100K per communication is enough.


Website: http://hallambaker.com/