Re: [perpass] Lauren Weinstein on Explicit Trusted Proxy in HTTP/2.0: "One of the Most Alarming Internet Proposals I've Ever Seen"

Patrick McManus <pmcmanus@mozilla.com> Mon, 24 February 2014 15:37 UTC

Return-Path: <patrick.ducksong@gmail.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8290A1A0130 for <perpass@ietfa.amsl.com>; Mon, 24 Feb 2014 07:37:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.423
X-Spam-Level: *
X-Spam-Status: No, score=1.423 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8xY844d9CeSq for <perpass@ietfa.amsl.com>; Mon, 24 Feb 2014 07:37:43 -0800 (PST)
Received: from mail-qc0-x22c.google.com (mail-qc0-x22c.google.com [IPv6:2607:f8b0:400d:c01::22c]) by ietfa.amsl.com (Postfix) with ESMTP id 8A83F1A012E for <perpass@ietf.org>; Mon, 24 Feb 2014 07:37:43 -0800 (PST)
Received: by mail-qc0-f172.google.com with SMTP id w7so6951194qcr.17 for <perpass@ietf.org>; Mon, 24 Feb 2014 07:37:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=aGmENmt7TbgL9IqlSEqIghYEaL0CuwYJ/FP6IARfKlE=; b=sg5RL138hYSjI1YFtEjV8hZ0zaNId2iiBQXGKC7Uspa4wHiD91PYqySYzJcyPhqz8U xgQqs5s+E8Nrnj4DgjvAcfLOqigCGGeFfMxLHIa1WvhCS5ePMHcVThGGbc6ujT0mSPA1 l9HENmQWvdvZ7tig9qmt032+HAhodMIcxcteHuOi96RV9GYDrNt3cposq//GzerqIGCR CnFFnO8chGAqfMl6h5VZsLrc9iRTgHupIFLevBbe+brwV7lEYSkGK/7NvnQ0vSA1kATa r5g/F6+giOM4yHKf/fX7mBAWuVYfJ7tAlSsjBJl9lTJlq34aXqDpDl/WlOIkbUqiOYhD t/Zg==
MIME-Version: 1.0
X-Received: by 10.140.92.213 with SMTP id b79mr29442133qge.108.1393256262892; Mon, 24 Feb 2014 07:37:42 -0800 (PST)
Sender: patrick.ducksong@gmail.com
Received: by 10.140.91.116 with HTTP; Mon, 24 Feb 2014 07:37:42 -0800 (PST)
In-Reply-To: <530B637E.4020308@ping.de>
References: <530B637E.4020308@ping.de>
Date: Mon, 24 Feb 2014 10:37:42 -0500
X-Google-Sender-Auth: eRuPt5dTOTCM7VtVi63PpXmUKC8
Message-ID: <CAOdDvNoZrfokUUtKAjkyfSvxORqwEot1RrTmLBgiASJq-RvFpw@mail.gmail.com>
From: Patrick McManus <pmcmanus@mozilla.com>
To: Andreas Kuckartz <a.kuckartz@ping.de>
Content-Type: multipart/alternative; boundary="001a113a49a0a1818104f328c052"
Archived-At: http://mailarchive.ietf.org/arch/msg/perpass/AEbJ5SN-nG0UJY165mhjsi96tnE
Cc: perpass <perpass@ietf.org>
Subject: Re: [perpass] Lauren Weinstein on Explicit Trusted Proxy in HTTP/2.0: "One of the Most Alarming Internet Proposals I've Ever Seen"
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Feb 2014 15:37:45 -0000

On Mon, Feb 24, 2014 at 10:21 AM, Andreas Kuckartz <a.kuckartz@ping.de>wrote:

> No, I Don't Trust You! -- One of the Most Alarming Internet Proposals
> I've Ever Seen
> http://lauren.vortex.com/archive/001076.html
>
> The name of that HTTPBis Working Group draft already sounds suspicious:
>
>
That is not an active document that has been adopted by the httpbis working
group. It is a related individual draft that has been submitted to the
working group for discussion. There's a big difference - there essentially
is no bar for submitting an individual draft but its how most things get
started. You can see the active vs related documents here
https://datatracker.ietf.org/wg/httpbis/



> Explicit Trusted Proxy in HTTP/2.0
> draft-loreto-httpbis-trusted-proxy20-01
> http://tools.ietf.org/html/draft-loreto-httpbis-trusted-proxy20-01
>
> I do not know the details of the processes of the IETF:
> What can I do to help kill that proposal?
>
>
I'd love to hear from you in the working group! Just make sure you read the
drafts in detail and have specific commentary.

In general for all IETF matters at this stage, read the mailing list to see
what has been said so far and then participate in the working group via
email and the announced face to face meetings (perhaps via one of the
remote mechanisms the IETF provides for them). Especially email. List
archive/subscription information for httpbis is linked off the datatracker
URL I provided above.