[perpass] on encryption and social networks (Was Last call: draft-farrell-perpass-attack-02)
Eliot Lear <lear@cisco.com> Wed, 11 December 2013 08:40 UTC
Return-Path: <lear@cisco.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E8C31ADF63 for <perpass@ietfa.amsl.com>; Wed, 11 Dec 2013 00:40:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.501
X-Spam-Level:
X-Spam-Status: No, score=-9.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a76op7zpZCRX for <perpass@ietfa.amsl.com>; Wed, 11 Dec 2013 00:40:53 -0800 (PST)
Received: from aer-iport-1.cisco.com (aer-iport-1.cisco.com [173.38.203.51]) by ietfa.amsl.com (Postfix) with ESMTP id 579351AE323 for <perpass@ietf.org>; Wed, 11 Dec 2013 00:40:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7879; q=dns/txt; s=iport; t=1386751247; x=1387960847; h=message-id:date:from:mime-version:to:cc:subject: references:in-reply-to; bh=ZZNFQ2mOcQUqBm4mB/P69W0xOOqLS8r/stfCQ8SzIhE=; b=SP1selEu9bO5+kjiJLtM6WOdcnH6j04cechEOfrH3Zwj8VG8P8glKJVJ wdLtPK5Jd8dKqE3AZJ2UcTbuom2PNuZ+RrJ2+3wSQZ17AheAv+JLYVC/7 OCzgaf0ZaA4xB065yME/OyiazeF8d0igVqUtoMesgOeIJHlJ5NwBzhZOI 8=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgcFAPAjqFKQ/khM/2dsb2JhbABZgwc4g1aFXbBDgSAWdIIlAQEBAgIOFUITARAjCRYLAgIJAwIBAgFFBg0BBwEBh34NsVCPVxeOIxEBUAeCbIFIBJFkhjCBMJBjgWuBPzuBNQ
X-IronPort-AV: E=Sophos;i="4.93,870,1378857600"; d="scan'208,217";a="1999310"
Received: from ams-core-3.cisco.com ([144.254.72.76]) by aer-iport-1.cisco.com with ESMTP; 11 Dec 2013 08:40:46 +0000
Received: from ams3-vpn-dhcp5477.cisco.com (ams3-vpn-dhcp5477.cisco.com [10.61.85.100]) by ams-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id rBB8egtA026251 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 11 Dec 2013 08:40:42 GMT
Message-ID: <52A8250A.7060604@cisco.com>
Date: Wed, 11 Dec 2013 09:40:42 +0100
From: Eliot Lear <lear@cisco.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:24.0) Gecko/20100101 Thunderbird/24.1.1
MIME-Version: 1.0
To: Stefan Winter <stefan.winter@restena.lu>
References: <20131203174852.21387.26099.idtracker@ietfa.amsl.com> <A3B306E3-846C-45BA-8ED9-13B96AA645A3@piuha.net> <002501cef266$b0b8a540$4001a8c0@gateway.2wire.net> <52A1A3AA.3080101@restena.lu> <009701cef2b3$f6c69400$4001a8c0@gateway.2wire.net>, <52A5786A.8040308@restena.lu>, <290E20B455C66743BE178C5C84F1240847E51037A1@EXMB01CMS.surrey.ac.uk> <290E20B455C66743BE178C5C84F1240847E51037A2@EXMB01CMS.surrey.ac.uk> <52A815AE.9070408@restena.lu>
In-Reply-To: <52A815AE.9070408@restena.lu>
X-Enigmail-Version: 1.6
Content-Type: multipart/alternative; boundary="------------090101030501060203080301"
Cc: perpass <perpass@ietf.org>, Mark Nottingham <mnot@mnot.net>
Subject: [perpass] on encryption and social networks (Was Last call: draft-farrell-perpass-attack-02)
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 08:40:55 -0000
Hi Stefan, On 12/11/13 8:35 AM, Stefan Winter wrote: > Hi, > >>> Knives are easily available to anyone, just like encryption. >> ...and just like pervasive monitoring? > That's a very good thought. > > Yes, I believe encrpytion and the ability to pervasively monitor are > both easily available to everyone. > > The next step after availability is actual usage, and this is where > things get interesting. > > I believe that where encryption is not actually *used*, pervasice > monitoring *will* happen. Or, to state it a bit more in a logic-oriented > way: > > Either the use of encryption proliferates, or the use of pervasive > monitoring proliferates. > > It is a strict XOR: you can't have both, and you can't have none of the two. Pervasive monitoring is not just about encryption, and I suspect you fully understand this, but have simplified your argument for the purposes of focusing on encryption. Even so, I like your analogy, in as much as you are not looking at one big XOR but many little small ones and then summing them on either side of the equation. That's the nature of engineering tradeoffs, to be fair. In reviewing some other work on another list, I came across a paper that talked about pervasive surveillance from an economics sense, written in 2006 entitled /The Economics of Mass Surveillance and the Questionable Value of Anonymous Communications/.[1] It's early work to be sure, and actually argues that the adversary has to actually do very little to achieve quite a lot in monitoring everyone. But it also alludes to the use of social network theory to answer questions of "who" not "what". While there are many different aspects of surveillance, social networks are clearly a component. Masking the "who" is much harder than the what, and yet the "who" may be as or more valuable. Unfortunately for us, the who can be represented by IP address (as an example). It's why there's some interest in TOR. Fortunately for us, use of services like Google or Facebook or Twitter provide a means to obscure paths of communication. Unfortunately for us, they become single points of failure.[*] This goes to a point that Mark Nottingham made in the plenary. How do we strike a balance between those single points of failure on the one hand and the potential benefits that some amount of aggregation can bring? There has been other related work on this topic from the context of platform diversity and cybersecurity, but I regret that I couldn't find the paper I wanted to cite for this email (I tried- it's there- maybe others can dig it up) that is worth some consideration. My point in raising this now and my point of intervening several times in the plenary is to highlight that many of the issues around pervasive surveillance are complex and have many tradeoffs to be made. There's some research to be reviewed, and perhaps some research to be performed. When we say that we the IETF are going to do something, we need to be looking at a long term view, while taking reasonable actions in the short term that heads us in the right direction. Eliot [1] http://weis2006.econinfosec.org/docs/36.pdf [*] I imagine there's an undiscovered Rogers and Hammerstein song called "Fortunately/Unfortunately" buried in here.
- [perpass] on encryption and social networks (Was … Eliot Lear
- Re: [perpass] on encryption and social networks (… Stefan Winter